First published: Wed Aug 15 2018(Updated: )
The acceptAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request forgery (CSRF) vulnerability.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Questions For Confluence | <2.6.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13394 is a vulnerability found in Atlassian Confluence Questions before version 2.6.6 that allows remote attackers to modify a comment into an answer via a Cross-site request forgery (CSRF) vulnerability.
The severity of CVE-2018-13394 is medium, with a severity value of 6.5.
CVE-2018-13394 affects Atlassian Confluence Questions before version 2.6.6, specifically the bundled version of Confluence Questions.
Remote attackers can exploit CVE-2018-13394 by modifying a comment into an answer through a Cross-site request forgery (CSRF) vulnerability.
Yes, a fixed version of Confluence Questions was included in Confluence version 6.9.0 to address CVE-2018-13394.