CVE-2018-13389: Atlassian Confluence

Medium severity, CVSS 4.7. EPSS: 1% chance of exploitation in the next 30 days.

The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attachments that have a content-type of application/rdf+xml.

Affected products

  • Atlassian Confluence: before 6.6.1 (fixed in 6.6.1)

Published 2018-07-10. Last modified 2026-06-17.