Description
The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and from 7.5.0 before 7.8.3 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
Remediation
References
Related Vulnerabilities
CakePHP Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-8379)
SharePoint Deserialization of Untrusted Data Vulnerability (CVE-2024-38023)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1559)
WordPress Plugin Realty by BestWebSoft Cross-Site Scripting (1.0.9)
WordPress 3.0.3 KSES Library Cross-Site Scripting Vulnerability (0.6.2 - 3.0.3)