First published: Tue Jan 07 2020(Updated: )
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the avatar upload feature. The affected versions are before version 7.2.0.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Confluence Data Center | <7.2.0 | |
Atlassian Confluence Server | <7.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-29450 is a Denial of Service (DoS) vulnerability in the avatar upload feature of Atlassian Confluence Server and Data Center.
CVE-2020-29450 allows remote attackers to impact the application's availability by exploiting the Denial of Service (DoS) vulnerability in the avatar upload feature.
CVE-2020-29450 affects versions of Atlassian Confluence Server and Data Center before version 7.2.0.
CVE-2020-29450 has a severity level of medium with a CVSS score of 6.5.
Yes, the fix for CVE-2020-29450 is included in version 7.2.0 of Atlassian Confluence Server and Data Center.