Description
The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and from 7.5.0 before 7.8.3 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
Remediation
References
Related Vulnerabilities
WordPress Plugin Shortcode Factory Local File Inclusion (2.7)
OpenSSL Cryptographic Issues Vulnerability (CVE-2013-6449)
WordPress Plugin weForms-Easy Drag & Drop Contact Form Builder CSV Injection (1.4.7)
WordPress Plugin WP e-Commerce-Store Exporter Privilege Escalation (1.6.6)
Resin Application Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2969)