CVE Vulnerabilities

CVE-2021-26085

Direct Request ('Forced Browsing')

Published: Aug 03, 2021 | Modified: Aug 08, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

Name Vendor Start Version End Version
Confluence_data_center Atlassian * 7.4.10 (excluding)
Confluence_data_center Atlassian 7.5.0 (including) 7.12.3 (excluding)
Confluence_server Atlassian * 7.4.10 (excluding)
Confluence_server Atlassian 7.5.0 (including) 7.12.3 (excluding)

Potential Mitigations

References