Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Katsuragicsl

#33628of 53,632
7.8Total CVSS
Vulnerabilities · 1
PT-2022-7389
7.8
2022-08-24
Atlassian · Confluence · CVE-2022-38900
**Name of the Vulnerable Software and Affected Versions** decode-uri-component version 0.2.0 Confluence Data Center versions 7.0.1 through 9.0.x **Description** The issue is related to improper input validation, which can result in a denial of service (DoS). This can be exploited by a remote attacker, allowing them to disrupt service availability. The vulnerability has a high impact on availability but does not affect confidentiality or integrity. It requires no user interaction to be exploited. **Recommendations** For decode-uri-component version 0.2.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Confluence Data Center versions 7.0.1 through 9.0.x, upgrade to Confluence Data Center 9.1.0 or a later version to resolve the issue. If upgrading to version 9.1.0 or later is not possible, upgrade to a release greater than or equal to 9.1.0.