CVE Vulnerabilities

CVE-2020-29448

Published: Feb 22, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and from 7.5.0 before 7.8.3 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.

Affected Software

NameVendorStart VersionEnd Version
Confluence_data_centerAtlassian*6.13.18 (excluding)
Confluence_data_centerAtlassian6.14.0 (including)7.4.6 (excluding)
Confluence_data_centerAtlassian7.5.0 (including)7.8.3 (excluding)
Confluence_serverAtlassian*6.13.18 (excluding)
Confluence_serverAtlassian6.14.0 (including)7.4.6 (excluding)
Confluence_serverAtlassian7.5.0 (including)7.8.3 (excluding)

References