Loading HuntDB...

GHSA-hfhf-22gm-76w3

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.

The affected versions are before version 7.19.9.

This vulnerability was discovered by Rojan Rijal of the Tinder Security Engineering Team.

Related CVEs

Key Information

GHSA ID
GHSA-hfhf-22gm-76w3
Published
May 25, 2023 3:30 PM
Last Modified
May 25, 2023 3:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.