First published: Wed Apr 15 2020(Updated: )
The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before version 6.15.5 allows remote attackers to achieve stored cross-site- scripting (SXSS) via a malicious attachment with a modified `mimeType` parameter.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Confluence Server | >=6.14.0<=6.14.3 | |
Atlassian Confluence Server | >=6.15.0<6.15.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20102 is a vulnerability in Atlassian Confluence Server that allows for stored cross-site scripting (SXSS) attacks via a malicious attachment.
CVE-2019-20102 affects Atlassian Confluence Server versions 6.14.0 through 6.14.3, and versions 6.15.0 before 6.15.5.
CVE-2019-20102 has a severity rating of medium with a CVSS score of 6.1.
Remote attackers can exploit CVE-2019-20102 by uploading a malicious attachment with a modified 'mimeType' parameter.
Yes, the fix for CVE-2019-20102 is to upgrade to Atlassian Confluence Server version 6.14.4 or version 6.15.5.