Loading HuntDB...

Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

Added March 28, 2022 Due April 18, 2022 CVE-2021-26085
Overdue Atlassian / Confluence Server Known Ransomware Use CWE-425

Description

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.

Required Action

Apply updates per vendor instructions.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
4 months, 1 week ago