Vulnerabilities
Vulnerable Software
Atlassian:  >> Confluence  >> 5.10.9  Security Vulnerabilities
Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of comments, for comments added to a page after they started watching it even if they do not have permission to view the page itself.
CVSS Score
4.3
EPSS Score
0.004
Published
2017-06-15


Contact Us

Shodan ® - All rights reserved