Description
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2022-21305 Vulnerability (CVE-2022-21305)
WordPress Plugin ArcadePress 'upload.php' Arbitrary File Upload (0.65)
MyBB Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-3967)
WordPress Plugin AzonPost Cross-Site Scripting (1.3)
Internet Information Services Configuration Vulnerability (CVE-2003-1566)