Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-22503


Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature. This vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team. The affected versions are before version 7.13.15, from version 7.14.0 before 7.19.7, and from version 7.20.0 before 8.2.0.


Published

2023-05-01T17:15:08.993

Last Modified

2024-11-21T07:44:56.947

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application atlassian confluence_data_center < 7.13.15 Yes
Application atlassian confluence_data_center < 7.19.7 Yes
Application atlassian confluence_data_center < 8.2.0 Yes
Application atlassian confluence_server < 7.13.15 Yes
Application atlassian confluence_server < 7.19.7 Yes
Application atlassian confluence_server < 8.2.0 Yes

References