Description
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.
Remediation
References
Related Vulnerabilities
WordPress 5.5.x PHP Object Injection (5.5 - 5.5.4)
WordPress Plugin Power Zoomer Arbitrary File Upload (1.2)
WordPress Plugin Integration for Contact Form 7 HubSpot Cross-Site Scripting (1.1.9)
WordPress Plugin Elementor Website Builder Arbitrary File Upload (3.18.1)
WordPress Plugin Restricted Site Access Unspecified Vulnerability (2.0)