Vulnerabilities > Atlassian > Confluence Data Center > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-05-01 CVE-2023-22503 Unspecified vulnerability in Atlassian Confluence Data Center
Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space.
network
low complexity
atlassian
5.3
2022-04-05 CVE-2021-39114 Code Injection vulnerability in Atlassian Confluence Data Center and Confluence Server
Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload.
network
low complexity
atlassian CWE-94
6.5
2022-02-15 CVE-2021-43940 Uncontrolled Search Path Element vulnerability in Atlassian Confluence Server
Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer.
6.9
2021-08-03 CVE-2021-26085 Forced Browsing vulnerability in Atlassian Confluence Server
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint.
network
low complexity
atlassian CWE-425
5.3
2021-04-01 CVE-2021-26072 Server-Side Request Forgery (SSRF) vulnerability in Atlassian Confluence Data Center and Confluence Server
The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.
network
low complexity
atlassian CWE-918
4.0
2021-02-22 CVE-2020-29448 Unspecified vulnerability in Atlassian Confluence Data Center and Confluence Server
The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and from 7.5.0 before 7.8.3 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
network
low complexity
atlassian
5.0
2021-01-19 CVE-2020-29450 Unrestricted Upload of File with Dangerous Type vulnerability in Atlassian Confluence Server
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the avatar upload feature.
network
low complexity
atlassian CWE-434
4.0
2019-02-13 CVE-2018-20237 Exposure of Resource to Wrong Sphere vulnerability in Atlassian Confluence Data Center and Confluence Server
Atlassian Confluence Server and Data Center before version 6.13.1 allows an authenticated user to download a deleted page via the word export feature.
network
low complexity
atlassian CWE-668
4.0