Impact
Atlassian Confluence Data Center contains a flaw that allows an authenticated user to trigger a denial of service by exhausting application resources. The vulnerability is rated CVSS 7.1 and is mapped to CWE-400. An attacker with valid credentials can generate requests that cause the Confluence process to become unresponsive or crash, making the service unavailable to legitimate users for a temporary or indefinite period.
Affected Systems
The issue impacts Confluence Data Center releases beginning with 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0. Based on the vendor recommendation, versions 9.2.24 and later, and 10.2.17 and later are not affected; therefore, the vulnerability likely exists in releases through 9.2.23 and 10.2.16 (inference). Users on these affected releases should not operate unless they apply the patched version. Atlassian recommends upgrading to 9.2.24 or later for the 9.2 series, and to 10.2.17 or later for the 10.2 series, or to the latest available release.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, yet the EPSS score of < 1% shows a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because the attacker requires authentication, the risk is mitigated by user credential controls, but once authenticated, the flaw can be leveraged to disrupt service. Organizations should treat this as a priority issue and implement the vendor’s fix promptly to prevent potential service outages.
OpenCVE Enrichment