CVE-2023-22504

Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-05-25 14:15

Updated : 2023-06-07 14:15


NVD link : CVE-2023-22504

Mitre link : CVE-2023-22504

CVE.ORG link : CVE-2023-22504


JSON object : View

Products Affected

atlassian

  • confluence_server
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type