Impact
A recently identified DoS vulnerability exists in Atlassian Confluence Data Center that enables an authenticated attacker to exhaust server resources and render the application unavailable for its intended users. The flaw is classified as a resource exhaustion weakness (CWE-400). Based on the description, it is inferred that the vulnerability is triggered by an attacker exploiting an authenticated session to repeatedly execute privileged operations that consume resources, potentially causing temporary or indefinite service disruption.
Affected Systems
This issue affects Atlassian Confluence Data Center, as detailed by the CNA. Versions impacted include 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0. The advisory recommends that instances running Confluence Data Center 9.2 be upgraded to any release 9.2.17 or later, and that 10.2 installations be upgraded to any release 10.2.7 or later, or to the latest available version overall.
Risk and Exploitability
The CVSS score of 7.1 reflects a moderate to high risk of availability compromise when exploited. The EPSS score of < 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker must first be authenticated within Confluence to exploit the flaw, implying an internal threat vector. The likely attack vector is the exploitation of an existing authenticated session to send repeated privileged requests that induce resource exhaustion, leading to denial of service for all users on the affected node.
OpenCVE Enrichment