5.3

CVE-2020-29448

The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and from 7.5.0 before 7.8.3 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AtlassianConfluence Data Center Version < 6.13.18
AtlassianConfluence Data Center Version >= 6.14.0 < 7.4.6
AtlassianConfluence Data Center Version >= 7.5.0 < 7.8.3
AtlassianConfluence Server Version < 6.13.18
AtlassianConfluence Server Version >= 6.14.0 < 7.4.6
AtlassianConfluence Server Version >= 7.5.0 < 7.8.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.529
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N