Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2023-22503", "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66", "state": "PUBLISHED", "assignerShortName": "atlassian", "dateReserved": "2023-01-01T00:01:22.329Z", "datePublished": "2023-05-01T16:00:32.509Z", "dateUpdated": "2024-10-01T15:22:41.837Z"}, "containers": {"cna": {"affected": [{"vendor": "Atlassian", "product": "Confluence Data Center", "versions": [{"version": "< 7.20.2", "status": "unaffected"}, {"version": ">= 7.20.2", "status": "affected"}, {"version": ">= 7.13.5", "status": "unaffected"}, {"version": ">= 7.19.7", "status": "unaffected"}, {"version": ">= 8.20.0", "status": "unaffected"}]}, {"vendor": "Atlassian", "product": "Confluence Server", "versions": [{"version": "< 7.20.2", "status": "unaffected"}, {"version": ">= 7.20.2", "status": "affected"}, {"version": ">= 7.13.5", "status": "unaffected"}, {"version": ">= 7.19.7", "status": "unaffected"}, {"version": ">= 8.20.0", "status": "unaffected"}]}], "descriptions": [{"lang": "en", "value": "Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature.\r\n\r\nThis vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team.\r\n\r\nThe affected versions are before version 7.13.15, from version 7.14.0 before 7.19.7, and from version 7.20.0 before 8.2.0."}], "problemTypes": [{"descriptions": [{"description": "Information Disclosure", "lang": "en", "type": "Information Disclosure"}]}], "references": [{"url": "https://jira.atlassian.com/browse/CONFSERVER-82403"}], "credits": [{"lang": "en", "value": "This vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team."}], "metrics": [{"cvssV3_0": {"version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM"}}], "providerMetadata": {"orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66", "shortName": "atlassian", "dateUpdated": "2023-05-01T16:00:32.509Z"}}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-02T10:13:48.665Z"}, "title": "CVE Program Container", "references": [{"url": "https://jira.atlassian.com/browse/CONFSERVER-82403", "tags": ["x_transferred"]}]}, {"problemTypes": [{"descriptions": [{"type": "CWE", "cweId": "CWE-200", "lang": "en", "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor"}]}], "affected": [{"vendor": "atlassian", "product": "confluence_data_center", "cpes": ["cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "0", "status": "affected", "lessThan": "7.13.15", "versionType": "custom"}, {"version": "7.14.0", "status": "affected", "lessThan": "7.19.7", "versionType": "custom"}, {"version": "7.20.0", "status": "affected", "lessThan": "8.2.0", "versionType": "custom"}]}, {"vendor": "atlassian", "product": "confluence_server", "cpes": ["cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "0", "status": "affected", "lessThan": "7.13.15", "versionType": "custom"}, {"version": "7.14.0", "status": "affected", "lessThan": "7.19.7", "versionType": "custom"}, {"version": "7.20.0", "status": "affected", "lessThan": "8.2.0", "versionType": "custom"}]}], "metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2024-10-01T15:14:47.693093Z", "id": "CVE-2023-22503", "options": [{"Exploitation": "none"}, {"Automatable": "yes"}, {"Technical Impact": "partial"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-10-01T15:22:41.837Z"}}]}}