CVE Vulnerabilities

CVE-2020-29448

Published: Feb 22, 2021 | Modified: Jul 27, 2022
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and from 7.5.0 before 7.8.3 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.

Affected Software

Name Vendor Start Version End Version
Confluence_data_center Atlassian * 6.13.18 (excluding)
Confluence_data_center Atlassian 6.14.0 (including) 7.4.6 (excluding)
Confluence_data_center Atlassian 7.5.0 (including) 7.8.3 (excluding)
Confluence_server Atlassian * 6.13.18 (excluding)
Confluence_server Atlassian 6.14.0 (including) 7.4.6 (excluding)
Confluence_server Atlassian 7.5.0 (including) 7.8.3 (excluding)

References