Several rest inline action resources of Atlassian Activity Streams before version 6.3.0 allows remote authenticated attackers to watch any Confluence page & receive notifications when comments are added to the watched page, and vote & watch JIRA issues that they do not have access to, although they will not receive notifications for the issue, via missing permission checks.
Advisories
Source ID Title
EUVD EUVD EUVD-2017-18445 Several rest inline action resources of Atlassian Activity Streams before version 6.3.0 allows remote authenticated attackers to watch any Confluence page & receive notifications when comments are added to the watched page, and vote & watch JIRA issues that they do not have access to, although they will not receive notifications for the issue, via missing permission checks.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: atlassian

Published:

Updated: 2024-09-17T02:53:33.339Z

Reserved: 2017-06-07T00:00:00

Link: CVE-2017-9513

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-01-29T19:29:01.063

Modified: 2024-11-21T03:36:18.327

Link: CVE-2017-9513

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.