CVE-2020-29450: Atlassian Confluence Data Center

Medium severity, CVSS 6.5. EPSS: 2.2% chance of exploitation in the next 30 days.

Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the avatar upload feature. The affected versions are before version 7.2.0.

Affected products

  • Atlassian Confluence Data Center: before 7.2.0 (fixed in 7.2.0)
  • Atlassian Confluence Server: before 7.2.0 (fixed in 7.2.0)

Published 2021-01-19. Last modified 2026-06-17.