CVE-2017-9505
Last modified
CVE-2017-9505 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of comments, for comments added to a page after they started watching it even if they do not have permission to view the page itself.. EPSS estimates a 1.26% chance of exploitation in the next 30 days.
Description
Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of comments, for comments added to a page after they started watching it even if they do not have permission to view the page itself.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Confluence | >= 4.3, < 6.2.1 |
References
- http://www.securityfocus.com/bid/99086Third Party Advisory, VDB Entry
- https://jira.atlassian.com/browse/CONFSERVER-52560Mitigation, Vendor Advisory
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170613-0_Atlassian_Confluence_Access_Restriction_Bypass_v10.txtExploit, Mitigation, Third Party Advisory
- http://www.securityfocus.com/bid/99086Third Party Advisory, VDB Entry
- https://jira.atlassian.com/browse/CONFSERVER-52560Mitigation, Vendor Advisory
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170613-0_Atlassian_Confluence_Access_Restriction_Bypass_v10.txtExploit, Mitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-9505?
How severe is CVE-2017-9505?
How do I fix CVE-2017-9505?
Are you affected by CVE-2017-9505?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
