Home

Description

The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before version 6.15.5 allows remote attackers to achieve stored cross-site- scripting (SXSS) via a malicious attachment with a modified `mimeType` parameter.

PUBLISHED Reserved 2019-12-30 | Published 2020-04-22 | Updated 2024-09-16 | Assigner atlassian

Problem types

Cross Site Scripting (XSS)

Product status

6.14.0 (custom) before unspecified
affected

Any version
affected

6.15.0 (custom) before unspecified
affected

Any version before 6.15.5
affected

References

jira.atlassian.com/browse/CONFSERVER-59358

jira.atlassian.com/browse/CONFSERVER-59358

cve.org (CVE-2019-20102)

nvd.nist.gov (CVE-2019-20102)

Download JSON