5.3
CVE-2020-29448
- EPSS 0.3%
- Veröffentlicht 22.02.2021 21:15:19
- Zuletzt bearbeitet 21.11.2024 05:24:01
- Quelle security@atlassian.com
- CVE-Watchlists
- Unerledigt
The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and from 7.5.0 before 7.8.3 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Atlassian ≫ Confluence Data Center Version < 6.13.18
Atlassian ≫ Confluence Data Center Version >= 6.14.0 < 7.4.6
Atlassian ≫ Confluence Data Center Version >= 7.5.0 < 7.8.3
Atlassian ≫ Confluence Server Version < 6.13.18
Atlassian ≫ Confluence Server Version >= 6.14.0 < 7.4.6
Atlassian ≫ Confluence Server Version >= 7.5.0 < 7.8.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.529 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|