CVE-2023-22505
- EPSS 2.06%
- Veröffentlicht 18.07.2023 21:15:15
- Zuletzt bearbeitet 21.11.2024 07:44:57
This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22505 was introduced in version 8.0.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8, allows an authenticated ...
CVE-2023-22503
- EPSS 0.79%
- Veröffentlicht 01.05.2023 17:15:08
- Zuletzt bearbeitet 21.11.2024 07:44:56
Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview ...
CVE-2022-42978
- EPSS 0.8%
- Veröffentlicht 15.11.2022 01:15:13
- Zuletzt bearbeitet 30.04.2025 18:15:35
In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated attacker could access files on the remote system.
CVE-2022-42977
- EPSS 0.96%
- Veröffentlicht 15.11.2022 01:15:13
- Zuletzt bearbeitet 30.04.2025 19:15:52
The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the functionality to generate a list of users in the application, and export it. During export, the HTTP request has a fileName parameter that accepts any file on the system (e.g....
CVE-2020-36290
- EPSS 0.66%
- Veröffentlicht 26.07.2022 04:15:11
- Zuletzt bearbeitet 21.11.2024 05:29:13
The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or Ja...
CVE-2022-26137
- EPSS 2.2%
- Veröffentlicht 20.07.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:53:30
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security...
CVE-2022-26136
- EPSS 5.02%
- Veröffentlicht 20.07.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:53:30
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulner...
CVE-2022-26134
- EPSS 100%
- Veröffentlicht 03.06.2022 22:15:07
- Zuletzt bearbeitet 24.10.2025 13:38:30
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1....
CVE-2021-39114
- EPSS 1.66%
- Veröffentlicht 05.04.2022 04:15:08
- Zuletzt bearbeitet 21.11.2024 06:18:36
Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions...
CVE-2021-43940
- EPSS 0.33%
- Veröffentlicht 15.02.2022 04:15:07
- Zuletzt bearbeitet 21.11.2024 06:30:02
Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This vulnerability only affects ins...