Description
Affected versions of Confluence Server before 7.4.8, and versions from 7.5.0 before 7.11.0 allow attackers to identify internal hosts and ports via a blind server-side request forgery vulnerability in Team Calendars parameters.
Remediation
References
Related Vulnerabilities
OpenSSL Possible denial of service attack Vulnerability (CVE-2020-1971)
WordPress Plugin Contact Form Email Multiple Vulnerabilities (1.2.65)
WordPress Plugin PICA Photo Gallery 'picaPhotosResize.php' Arbitrary File Upload (1.0)
Perl Numeric Errors Vulnerability (CVE-2011-2939)
WordPress Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2003-1599)