CVE-2017-7415: Atlassian Confluence Server

High severity, CVSS 7.5. EPSS: 4.5% chance of exploitation in the next 30 days.

Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST resource.

Affected products

  • Atlassian Confluence Server: version 6.0.0 only; version 6.0.1 only; version 6.0.2 only; version 6.0.3 only; version 6.0.4 only; version 6.0.5 only; …

Published 2017-04-27. Last modified 2026-06-17.