CVE-2018-20237: Medium severity atlassian confluence server/data center vulnerability
Published Feb 13, 2019
·Updated
Atlassian Confluence Server and Data Center before version 6.13.1 allows an authenticated user to download a deleted page via the word export feature.
Affected Software
4 affected components
Atlassian Confluence Data Center<6.13.1
Atlassian Confluence Data Center>=6.13.2<6.14.0
Atlassian Confluence Server<6.13.1
Atlassian Confluence Server>=6.13.2<6.14.0
Event History
Feb 13, 2019
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2018-20237.
2
What is the severity of CVE-2018-20237?
The severity of CVE-2018-20237 is medium with a CVSS score of 6.5.
3
Which versions of Atlassian Confluence Server and Data Center are affected by CVE-2018-20237?
Atlassian Confluence Server and Data Center versions up to 6.13.1 are affected by CVE-2018-20237.
4
How can an authenticated user exploit CVE-2018-20237?
An authenticated user can exploit CVE-2018-20237 by downloading a deleted page via the word export feature.
5
Where can I find more information about CVE-2018-20237?
You can find more information about CVE-2018-20237 on the following references: [1](http://www.securityfocus.com/bid/107041), [2](https://jira.atlassian.com/browse/CONFSERVER-57814), [3](https://www.excellium-services.com/cert-xlm-advisory/cve-2018-20237/).