Impact
This vulnerability is a high‑severity information disclosure that was introduced in multiple Confluence Data Center releases, including versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0. It permits an unauthenticated attacker to view sensitive data through a flaw identified as CWE‑200. The CVSS score of 8.2 reflects the potential loss of confidentiality for an attacker without authentication.
Affected Systems
Affected systems are Atlassian Confluence Data Center deployments running any of the above versions, including any build of the 9.2 and 10.2 series that do not meet the minimum upgrade thresholds. Users of the 9.2 series must upgrade to a release equal to or newer than 9.2.22, while those on 10.2 must upgrade to 10.2.14 or later. All earlier 7.x and 8.x series versions that are still in use are also vulnerable.
Risk and Exploitability
The risk is high, with an EPSS score below 1 % indicating low current exploitation probability, and the vulnerability is not listed in CISA KEV. Attackers can exploit the flaw remotely without credentials, typically by sending a crafted request to the Confluence Data Center API or web interface that leaks internal information. Remediation is straightforward through an official patch; delaying the update unnecessarily leaves the system exposed to potential future exploitation.
OpenCVE Enrichment