PT-2016-3902 · Atlassian · Confluence

Sebastian Perez

·

Publicado

2016-04-11

·

Atualizado

2018-10-09

·

CVE-2015-8399

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Atlassian Confluence versions prior to 5.8.17
Description The issue allows remote authenticated users to read configuration files. This can be achieved by manipulating the decoratorName parameter in specific API endpoints, such as "/spaces/viewdefaultdecorator.action" or "/admin/viewdefaultdecorator.action".
Recommendations For versions prior to 5.8.17, update to version 5.8.17 or later to resolve the issue. As a temporary workaround, consider restricting access to the decoratorName parameter in the affected API endpoints until a patch is available.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-8399

Produtos afetados

Confluence