Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of comments, for comments added to a page after they started watching it even if they do not have permission to view the page itself.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/99086 | vdb entry third party advisory |
https://jira.atlassian.com/browse/CONFSERVER-52560 | mitigation vendor advisory |
https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170613-0_Atlassian_Confluence_Access_Restriction_Bypass_v10.txt | exploit third party advisory mitigation |