CVE-2021-26085: Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Atlassian Confluence Server and Data Serverto a version that resolves this vulnerability.Fixed in 7.4.10 - Upgrade
Upgrade
Atlassian Confluence Server and Data Serverto a version that resolves this vulnerability.Fixed in 7.12.3
Event History
Frequently Asked Questions
What is CVE-2021-26085?
CVE-2021-26085 refers to the Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability.
How does CVE-2021-26085 affect Atlassian Confluence Server?
CVE-2021-26085 allows remote attackers to view restricted resources in Atlassian Confluence Server.
Which versions of Atlassian Confluence Server are affected by CVE-2021-26085?
Affected versions of Atlassian Confluence Server are before version 7.4.10 and from version 7.5.0 before 7.12.3.
What is the severity of CVE-2021-26085?
CVE-2021-26085 has a severity rating of medium (5.3).
How can I fix the CVE-2021-26085 vulnerability in Atlassian Confluence Server?
To fix the CVE-2021-26085 vulnerability, you should update Atlassian Confluence Server to version 7.4.10 or later, or between version 7.5.0 and 7.12.3.