CVE-2021-26072
- EPSS 8.7%
- Veröffentlicht 01.04.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:55:48
The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.
CVE-2020-29448
- EPSS 0.3%
- Veröffentlicht 22.02.2021 21:15:19
- Zuletzt bearbeitet 21.11.2024 05:24:01
The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and from 7.5.0 before 7.8.3 allowed unauthenticated remote attackers to read arbitrary files within WEB-...
CVE-2020-29450
- EPSS 0.73%
- Veröffentlicht 19.01.2021 01:15:14
- Zuletzt bearbeitet 21.11.2024 05:24:01
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the avatar upload feature. The affected versions are before version 7.2.0.
CVE-2020-14175
- EPSS 0.23%
- Veröffentlicht 24.07.2020 07:15:14
- Zuletzt bearbeitet 21.11.2024 05:02:48
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in user macro parameters. The affected versions are before version 7.4.2, an...
CVE-2020-4027
- EPSS 0.22%
- Veröffentlicht 01.07.2020 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:32:10
Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template injection mitigations via an injection vulnerability in custom user macros. The affected vers...
CVE-2019-20102
- EPSS 0.42%
- Veröffentlicht 22.04.2020 04:15:10
- Zuletzt bearbeitet 21.11.2024 04:38:04
The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before version 6.15.5 allows remote attackers to achieve stored cross-site- scripting (SXSS) via a malicious attachment wit...
CVE-2019-20406
- EPSS 0.16%
- Veröffentlicht 06.02.2020 03:15:10
- Zuletzt bearbeitet 21.11.2024 04:38:24
The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path envi...
CVE-2019-15006
- EPSS 1.07%
- Veröffentlicht 19.12.2019 01:15:10
- Zuletzt bearbeitet 21.11.2024 04:27:51
There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center. This plugin was used to facilitate communication with the Atlassian Companion application. The Confluence Pr...
CVE-2019-3394
- EPSS 75.77%
- Veröffentlicht 29.08.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:42:01
There was a local file disclosure vulnerability in Confluence Server and Confluence Data Center via page exporting. An attacker with permission to editing a page is able to exploit this issue to read arbitrary file on the server under <install-direct...
CVE-2018-20239
- EPSS 0.41%
- Veröffentlicht 30.04.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:08
Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cro...