First published: Wed Aug 15 2018(Updated: )
The convertCommentToAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request forgery (CSRF) vulnerability.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Questions For Confluence | <2.6.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-13393.
CVE-2018-13393 has a severity level of medium (6.5).
CVE-2018-13393 affects Atlassian Confluence Questions before version 2.6.6.
CVE-2018-13393 allows remote attackers to modify a comment into an answer via a Cross-site request forgery (CSRF) vulnerability.
Yes, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0.