« Volver al listado

CVE-2023-22503

Estado: ModificadaMedia (5.3)—

Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature.

This vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team.

The affected versions are before version 7.13.15, from version 7.14.0 before 7.19.7, and from version 7.20.0 before 8.2.0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-22503",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-22503",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-01T15:14:47.693093Z"
        }
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "security@atlassian.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@atlassian.com",
      "affectedData": [
        {
          "vendor": "Atlassian",
          "product": "Confluence Data Center",
          "versions": [
            {
              "status": "unaffected",
              "version": "< 7.20.2"
            },
            {
              "status": "affected",
              "version": ">= 7.20.2"
            },
            {
              "status": "unaffected",
              "version": ">= 7.13.5"
            },
            {
              "status": "unaffected",
              "version": ">= 7.19.7"
            },
            {
              "status": "unaffected",
              "version": ">= 8.20.0"
            }
          ]
        },
        {
          "vendor": "Atlassian",
          "product": "Confluence Server",
          "versions": [
            {
              "status": "unaffected",
              "version": "< 7.20.2"
            },
            {
              "status": "affected",
              "version": ">= 7.20.2"
            },
            {
              "status": "unaffected",
              "version": ">= 7.13.5"
            },
            {
              "status": "unaffected",
              "version": ">= 7.19.7"
            },
            {
              "status": "unaffected",
              "version": ">= 8.20.0"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*"
          ],
          "vendor": "atlassian",
          "product": "confluence_data_center",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "7.13.15",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "7.14.0",
              "lessThan": "7.19.7",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "7.20.0",
              "lessThan": "8.2.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*"
          ],
          "vendor": "atlassian",
          "product": "confluence_server",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "7.13.15",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "7.14.0",
              "lessThan": "7.19.7",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "7.20.0",
              "lessThan": "8.2.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2023-05-01T17:15:08.993",
  "references": [
    {
      "url": "https://jira.atlassian.com/browse/CONFSERVER-82403",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ],
      "source": "security@atlassian.com"
    },
    {
      "url": "https://jira.atlassian.com/browse/CONFSERVER-82403",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature.\r\n\r\nThis vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team.\r\n\r\nThe affected versions are before version 7.13.15, from version 7.14.0 before 7.19.7, and from version 7.20.0 before 8.2.0."
    }
  ],
  "lastModified": "2026-06-17T05:35:35.943",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ACD9E451-29B3-4D59-88E5-9AAB52C64B29",
              "versionEndExcluding": "7.13.15"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D6EA4793-BF98-4C48-9B80-90487A33B8C2",
              "versionEndExcluding": "7.19.7",
              "versionStartIncluding": "7.14.0"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D5FBFE8-F97B-4E6B-B6AB-7EF9955B66BA",
              "versionEndExcluding": "8.2.0",
              "versionStartIncluding": "7.20.0"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A9A23C3-4831-4882-9786-F63F8990206C",
              "versionEndExcluding": "7.13.15"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9F35096-F530-45EA-827F-56537235CCE3",
              "versionEndExcluding": "7.19.7",
              "versionStartIncluding": "7.14.0"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBBB9EBB-FFFA-4AE8-BA5A-D06D6D9A309E",
              "versionEndExcluding": "8.2.0",
              "versionStartIncluding": "7.20.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@atlassian.com"
}