First published: Tue Nov 15 2022(Updated: )
In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated attacker could access files on the remote system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Confluence Data Center | <1.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42978 refers to a vulnerability in the Netic User Export add-on for Atlassian Confluence, where authorization is mishandled allowing unauthenticated access to files on the remote system.
CVE-2022-42978 has a severity rating of 7.5 (High).
CVE-2022-42978 affects Atlassian Confluence Data Center versions up to and excluding 1.3.5.
The Common Weakness Enumeration (CWE) ID associated with CVE-2022-42978 is CWE-863.
Yes, updating the Netic User Export add-on to version 1.3.5 or later will fix CVE-2022-42978.