CVE-2017-9513: Medium severity atlassian activity streams vulnerability
Several rest inline action resources of Atlassian Activity Streams before version 6.3.0 allows remote authenticated attackers to watch any Confluence page & receive notifications when comments are added to the watched page, and vote & watch JIRA issues that they do not have access to, although they will not receive notifications for the issue, via missing permission checks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9513?
The severity of CVE-2017-9513 is medium, with a score of 5.4.
How do I fix CVE-2017-9513?
To fix CVE-2017-9513, upgrade Atlassian Activity Streams to version 6.3.0 or later.
Who is affected by CVE-2017-9513?
CVE-2017-9513 affects all versions of Atlassian Activity Streams prior to 6.3.0.
What types of attacks are possible due to CVE-2017-9513?
CVE-2017-9513 allows remote authenticated attackers to access notifications and watch Confluence pages and JIRA issues they do not have permission to view.
What is the nature of the vulnerability in CVE-2017-9513?
CVE-2017-9513 is a vulnerability that allows unauthorized access to Confluence page notifications and JIRA issue watching.