Loading HuntDB...

GHSA-63p3-c254-6c5g

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5 (the fixed version for 6.8.x), and from version 6.9.0 before 6.9.3 (the fixed version for 6.9.x) allows remote attackers to send arbitrary HTTP and WebDAV requests from a Confluence Server or Data Center instance via Server-Side Request Forgery.

Related CVEs

Key Information

GHSA ID
GHSA-63p3-c254-6c5g
Published
May 13, 2022 1:04 AM
Last Modified
May 13, 2022 1:04 AM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 12, 2025 6:34 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.