Lucene search

K
atlassianF100d1de8639CONFSERVER-52560
HistoryJun 08, 2017 - 2:49 a.m.

Access Restriction Bypass using watch notifications (CVE-2017-9505)

2017-06-0802:49:47
f100d1de8639
jira.atlassian.com
11

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

51.1%

Confluence did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of comments, for comments added to a page after they started watching it even if they do not have permission to view the page itself.

Affected versions:

  • Versions of Confluence starting with 4.3.0 before 6.2.1 are affected by this vulnerability.

Fix:

Workaround

If you are unable to upgrade to the fixed version or newer and need a workaround, you will need to disable in-app notifications from workbox as per the instructions [found here|https://confluence.atlassian.com/doc/configuring-workbox-notifications-301663830.html]:

Navigate to !https://confluence.atlassian.com/download/attachments/590259974/Cog.png! > General Configuration

Choose In-app Notifications in the left-hand panel

Select does not provide in-app notifications.

The workbox icon !https://confluence.atlassian.com/conf61/files/877187111/877187147/1/1489126934141/WorkboxIcon.png! will disappear from the Confluence top menu bar.

Acknowledgements
Atlassian would like to credit Mathias Frank of SEC Consult Vulnerability Lab for reporting this issue to us.

Affected configurations

Vulners
Node
atlassianconfluence_data_centerRangeā‰¤4.3
OR
atlassianconfluence_data_centerRangeā‰¤5.9.14
OR
atlassianconfluence_data_centerRangeā‰¤6.1.1
OR
atlassianconfluence_data_centerRange<6.2.1
VendorProductVersionCPE
atlassianconfluence_data_center*cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

51.1%