CVE-2022-42978: High severity Atlassian Confluence Data Center vulnerability
Published Nov 15, 2022
·Updated
In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated attacker could access files on the remote system.
Affected Software
1 affected component
Atlassian Confluence Data Center<1.3.5
Event History
Nov 15, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-42978?
CVE-2022-42978 refers to a vulnerability in the Netic User Export add-on for Atlassian Confluence, where authorization is mishandled allowing unauthenticated access to files on the remote system.
2
What is the severity of CVE-2022-42978?
CVE-2022-42978 has a severity rating of 7.5 (High).
3
How does CVE-2022-42978 affect Atlassian Confluence Data Center?
CVE-2022-42978 affects Atlassian Confluence Data Center versions up to and excluding 1.3.5.
4
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2022-42978?
The Common Weakness Enumeration (CWE) ID associated with CVE-2022-42978 is CWE-863.
5
Is there a fix available for CVE-2022-42978?
Yes, updating the Netic User Export add-on to version 1.3.5 or later will fix CVE-2022-42978.