CVE-2023-22503

Severity
5.3MEDIUM
EPSS
0.4%
top 40.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 1

Description

Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature. This vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team. The affected versions are before version 7.13.15, from version 7.14.0 before 7.19.7, and from version 7.20.0 before 8.2.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

NVDatlassian/confluence_data_center7.14.07.19.7+2
NVDatlassian/confluence_server7.14.07.19.7+2
CVEListV5atlassian/confluence_server>= 7.20.2

🔴Vulnerability Details

2
CVEList
CVE-2023-22503: Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a pri2023-05-01
GHSA
GHSA-7823-23gq-8g79: Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a pri2023-05-01