CVE Vulnerabilities

CVE-2020-29448

Published: Feb 22, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and from 7.5.0 before 7.8.3 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.

Affected Software

Name Vendor Start Version End Version
Confluence_data_center Atlassian * 6.13.18 (excluding)
Confluence_data_center Atlassian 6.14.0 (including) 7.4.6 (excluding)
Confluence_data_center Atlassian 7.5.0 (including) 7.8.3 (excluding)
Confluence_server Atlassian * 6.13.18 (excluding)
Confluence_server Atlassian 6.14.0 (including) 7.4.6 (excluding)
Confluence_server Atlassian 7.5.0 (including) 7.8.3 (excluding)

References