Lucene search

K
cvelistAtlassianCVELIST:CVE-2017-9505
HistoryJun 15, 2017 - 4:00 p.m.

CVE-2017-9505

2017-06-1516:00:00
atlassian
www.cve.org
6

AI Score

4.4

Confidence

High

EPSS

0.001

Percentile

51.1%

Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of comments, for comments added to a page after they started watching it even if they do not have permission to view the page itself.

CNA Affected

[
  {
    "product": "Confluence Server",
    "vendor": "Atlassian",
    "versions": [
      {
        "status": "affected",
        "version": "Versions of Confluence starting with 4.3.0 before 6.2.1 are affected by this vulnerability."
      }
    ]
  }
]

AI Score

4.4

Confidence

High

EPSS

0.001

Percentile

51.1%

Related for CVELIST:CVE-2017-9505