Vulnerabilities > CVE-2017-9513 - Missing Authorization vulnerability in Atlassian Activity Streams
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
Several rest inline action resources of Atlassian Activity Streams before version 6.3.0 allows remote authenticated attackers to watch any Confluence page & receive notifications when comments are added to the watched page, and vote & watch JIRA issues that they do not have access to, although they will not receive notifications for the issue, via missing permission checks.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |