Vulnerability Description
Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST resource.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Confluence Server | 6.0.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/97961Third Party AdvisoryVDB Entry
- https://jira.atlassian.com/browse/CONFSERVER-52222Issue TrackingVendor Advisory
- https://packetstormsecurity.com/files/142330/Confluence-6.0.x-Information-DiscloExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/97961Third Party AdvisoryVDB Entry
- https://jira.atlassian.com/browse/CONFSERVER-52222Issue TrackingVendor Advisory
- https://packetstormsecurity.com/files/142330/Confluence-6.0.x-Information-DiscloExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2017-7415?
CVE-2017-7415 is a vulnerability with a CVSS score of 7.5 (HIGH). Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST resource.
How severe is CVE-2017-7415?
CVE-2017-7415 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7415?
Check the references section above for vendor advisories and patch information. Affected products include: Atlassian Confluence Server.