CVE Database
/

CVE-2017-9505

Back to search

CVE-2017-9505

Published: Jun 15, 2017

Modified: Oct 16, 2024

PUBLISHED

Description

Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of comments, for comments added to a page after they started watching it even if they do not have permission to view the page itself.

VendorProductVersions

Atlassian

Confluence Server

affected
Versions of Confluence starting with 4.3.0 before 6.2.1 are affected by this vulnerability.

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now