Executive brief
Atlassian Confluence Server and Data Center are vulnerable to a pre-authorization arbitrary file read via the /s/ endpoint. Remote attackers can exploit this to view restricted resources without authentication.
Affected products
- Atlassian Confluence Server < 7.4.10, 7.5.0 to < 7.12.3
- Atlassian Confluence Data Center < 7.4.10, 7.5.0 to < 7.12.3
Timeline
- 2021-08-02: disclosed: NVD Published Date
- 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-28: advisory: External advisory publication date