CVE-2021-26085

5.3MEDIUM

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected version

公開日: 8/3/2021更新日: 10/24/2025

CISA既知の悪用された脆弱性

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.

必要な対応:

Apply updates per vendor instructions.

期限:

2022-04-18

既知のランサムウェア使用

説明

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

AI分析AIによる分析

影響を受ける製品

atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_server
atlassianconfluence_server

利用可能なエクスプロイト (1)

参照