Loading HuntDB...

GHSA-7823-23gq-8g79

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature.

This vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team.

The affected versions are before version 7.13.15, from version 7.14.0 before 7.19.7, and from version 7.20.0 before 8.2.0.

Related CVEs

Key Information

GHSA ID
GHSA-7823-23gq-8g79
Published
May 1, 2023 6:30 PM
Last Modified
May 1, 2023 6:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.