CVE-2020-4027
Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template injection mitigations via an injection vulnerability in custom user macros.
Does this matter?
Lower severity and a low EPSS score (1.52%). Track it; it rarely justifies an emergency change on its own.
Description
Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template injection mitigations via an injection vulnerability in custom user macros. The affected versions are before version 7.4.5, and from version 7.5.0 before 7.5.1.
- CVSS 3.1
- 4.7 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 1.52% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- atlassian/confluence · atlassian/confluence server
- Source
- security@atlassian.com
References
- https://jira.atlassian.com/browse/CONFSERVER-59898Issue Tracking, Patch, Release Notes, Vendor Advisory
- https://jira.atlassian.com/browse/CONFSERVER-59898Issue Tracking, Patch, Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.