CVE-2023-22504: Atlassian Confluence Server

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.

Affected products

  • Atlassian Confluence Server: before 7.13.17 (fixed in 7.13.17); from 7.14.0, before 7.19.9 (fixed in 7.19.9); from 7.20.0, before 8.2.2 (fixed in 8.2.2)

Published 2023-05-25. Last modified 2026-06-17.