CVE-2023-22504: Malicious File Upload
Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.
The affected versions are before version 7.19.9.
This vulnerability was discovered by Rojan Rijal of the Tinder Security Engineering Team.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-22504?
CVE-2023-22504 is a vulnerability in Atlassian Confluence Server that allows remote attackers with read permissions to upload attachments via a Broken Access Control vulnerability.
What are the affected versions of Atlassian Confluence Server?
The affected versions are before version 7.19.9.
How severe is CVE-2023-22504?
CVE-2023-22504 has a severity value of 6.5, which is considered medium.
How can I fix CVE-2023-22504?
To fix CVE-2023-22504, you should upgrade your Atlassian Confluence Server to version 7.19.9 or later.
Where can I find more information about CVE-2023-22504?
You can find more information about CVE-2023-22504 at the following reference link: [https://jira.atlassian.com/browse/CONFSERVER-83218](https://jira.atlassian.com/browse/CONFSERVER-83218)