CVE-2018-20237
published 2019-02-13CVE-2018-20237: Atlassian Confluence Server and Data Center before version 6.13.1 allows an authenticated user to download a deleted page via the word export feature.
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.74%
75.2th percentile
Atlassian Confluence Server and Data Center before version 6.13.1 allows an authenticated user to download a deleted page via the word export feature.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | confluence_data_center | < 6.13.1 | 6.13.1 |
| atlassian | confluence_data_center | >= 6.13.2 < 6.14.0 | 6.14.0 |
| atlassian | confluence_data_center | >= unspecified < 6.13.1 | 6.13.1 |
| atlassian | confluence_server | < 6.13.1 | 6.13.1 |
| atlassian | confluence_server | >= 6.13.2 < 6.14.0 | 6.14.0 |
| atlassian | confluence_server | >= unspecified < 6.13.1 | 6.13.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/107041https://jira.atlassian.com/browse/CONFSERVER-57814https://www.excellium-services.com/cert-xlm-advisory/cve-2018-20237/http://www.securityfocus.com/bid/107041https://jira.atlassian.com/browse/CONFSERVER-57814https://www.excellium-services.com/cert-xlm-advisory/cve-2018-20237/
2019-02-13
Published