Lucene search

K
atlassianRichatkinsCONFSERVER-32557
HistoryFeb 10, 2014 - 5:56 a.m.

Security vulnerability in apache commons fileupload

2014-02-1005:56:15
richatkins
jira.atlassian.com
15

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.191

Percentile

96.3%

Apache commons-fileupload 1.3.1 was released this weekend with a fix for CVE-2014-0050, involving a DoS attack when using specially crafted multipart requests. We need to determine if Confluence is vulnerable, and if so, upgrade to this version of the library.

Affected configurations

Vulners
Node
atlassianconfluence_data_centerRange5.4.3
OR
atlassianconfluence_data_centerRange<5.4.4
OR
atlassianconfluence_data_centerRange<5.4-OD-20
VendorProductVersionCPE
atlassianconfluence_data_center*cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.191

Percentile

96.3%