Known vulnerabilities in Confluence Server 7.17.3 - page 3
Vendor:
Atlassian
Software:
Confluence Server
Version:
7.17.3
Software CPE:
cpe:2.3:a:atlassian:atlassian_confluence_server:*:*:*:*:*:*:*:*
Website:
https://www.atlassian.com
Total vulnerabilities:
59
Public exploits:
7
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
10.2.17
9.2.24
10.2.15
9.2.23
10.2.14
9.2.22
10.2.13
9.2.21
10.2.11
9.2.20
1.0.0
3.0
10.2.10
9.2.19
9.2.17
10.1.2
10.2.7
10.2.6
9.2.15
10.2.3
9.2.14
8.5.31
10.2.2
9.2.13
10.2.1
9.2.12
8.5.30
10.2.0
9.2.11
8.5.29
9.2.10
8.5.28
10.1.1
10.1.0
9.2.9
8.5.27
9.2.8
10.0.3
9.0.3
10.0.2
9.5.4
9.5.3
9.2.7
8.5.26
8.5.25
10.0.1
8.5.24
9.5.2
9.2.6
9.2.5
8.5.23
9.5.1
9.5.0
8.5.22
9.2.4
9.4.1
9.3.2
8.5.21
9.2.3
9.4.0
9.2.2
8.5.20
9.3.1
8.5.19
9.2.1
7.19.30
8.5.18
9.2.0
8.9.8
7.19.29
8.5.17
9.1.1
9.1.0
8.9.7
8.5.16
7.19.28
8.9.6
8.5.15
7.19.27
9.0.2
9.0.0
8.5.14
7.19.26
9.0.1
8.9.5
8.9.4
7.19.25
8.5.12
7.19.24
8.9.3
8.5.11
8.9.2
8.5.10
7.19.23
7.19.22
8.5.9
8.9.1
8.5.8
8.9.0
7.19.21
8.8.1
7.19.20
8.5.7
8.8.0
8.5.6
7.19.19
7.19.18
8.7.2
8.7.0
8.5.5
8.7.1
8.5.4
7.19.17
8.6.2
8.4.5
8.5.3
8.6.1
7.19.16
8.1.4
8.6.0
8.5.2
8.4.4
8.3.4
7.19.15
8.5.1
8.4.3
8.3.3
7.19.14
7.19.12
8.5.0
8.4.2
7.13.20
8.4.1
7.19.11
7.13.19
8.4.0
7.13.18
7.19.10
8.3.2
8.3.1
7.19.9
7.13.17
8.3.0
8.2.3
7.13.16
8.2.2
7.19.8
8.2.1
8.2.0
8.1.3
8.1.1
8.1.0
7.19.7
7.19.6
7.13.15
7.13.14
7.10.2
7.9.3
7.8.3
7.7.4
7.6.3
7.13.13
8.0.4
7.19.5
8.0.3
8.0.2
7.19.4
8.0.1
8.0.0
7.20.3
7.20.2
7.13.12
7.13.11
7.19.3
7.20.1
7.19.2
7.20.0
7.13.9
7.19.1
7.19.0
7.18.3
7.13.8
7.18.2
7.16.5
7.4.18
7.15.3
7.14.4
7.17.5
7.18.1
7.13.7
7.18.0
7.17.4
7.16.4
7.15.2
7.14.3
7.13.6
7.4.17
7.17.3
7.17.2
7.13.5
7.17.1
7.14.2
7.4.16
7.17.0
7.4.15
7.16.3
7.16.2
7.16.1
7.13.4
7.4.14
7.16.0
7.15.1
7.15.0
7.14.1
7.14.0
7.13.3
7.13.2
7.13.1
7.13.0
7.4.13
7.4.12
6.13.23
6.13.22
7.4.11
7.11.6
7.11.5
7.11.4
7.12.5
7.12.4
7.12.3
7.11.3
7.4.10
7.4.9
6.13.21
7.12.2
7.12.1
7.4.8
7.12.0
7.11.2
6.13.20
7.11.1
7.11.0
7.10.1
7.10.0
7.6.2
7.4.7
7.4.6
6.13.19
7.9.1
7.4.5
7.2.1
6.13.18
7.9.0
7.8.1
7.8.0
7.4.4
6.13.17
6.13.15
7.7.3
7.4.3
7.7.2
7.4.1
7.6.1
7.6.0
6.13.13
7.5.2
7.5.1
7.5.0
7.4.0
7.3.5
7.3.4
7.3.3
7.3.2
7.3.1
7.2.2
6.13.12
6.13.11
7.2.0
7.1.2
7.1.1
7.1.0
7.0.5
7.0.4
7.0.3
7.0.2
7.0.1
6.15.10
6.15.9
6.15.8
6.15.7
6.15.6
6.15.4
6.15.2
6.15.1
6.14.3
6.14.2
6.14.1
6.14.0
6.13.10
6.13.9
6.13.8
6.13.7
6.13.6
6.13.5
6.13.4
6.13.3
6.13.2
6.13.1
6.13.0
6.12.4
6.12.3
6.12.2
6.12.1
6.12.0
6.11.2
6.11.1
6.11.0
6.10.3
6.10.2
6.10.1
6.10.0
6.9.3
6.9.1
6.9.0
6.8.5
6.8.3
6.8.2
6.8.1
6.8.0
6.7.3
6.7.2
6.7.1
6.6.17
6.6.16
6.6.15
6.6.14
6.6.13
6.6.12
6.6.11
6.6.10
6.6.9
6.6.8
6.6.7
6.6.6
6.6.5
6.6.4
6.6.3
6.6.2
6.6.0
6.5.3
6.5.2
6.5.0
6.4.0
6.3.4
6.3.2
6.2.2
6.2.1
6.2.0
6.1.4
6.1.3
6.1.2
6.1.1
6.1.0
6.0.7
6.0.6
6.0.5
6.0.4
6.0.3
6.0.2
6.0.1
5.10.9
5.10.8
5.10.7
5.10.6
5.10.4
5.10.3
5.10.2
5.10.1
5.10.0
5.9.14
5.9.12
5.9.11
5.9.10
5.9.9
5.9.8
5.9.7
5.9.6
5.9.5
5.9.4
5.9.3
5.9.2
5.9.1
5.8.18
5.8.17
5.8.16
5.8.15
5.8.14
5.8.13
5.8.10
5.8.9
5.8.8
5.8.6
5.8.5
5.8.4
5.8.2
5.7.6
5.7.5
5.7.4
5.7.3
5.7.1
5.7
5.6.6
5.6.5
5.6.4
5.6.3
5.6.1
5.5.7
5.5.6
5.5.3
5.5.2
5.5.1
5.5
5.4.4
5.4.3
5.4.2
5.4.1
5.4
5.3.4
5.3.1
5.3
5.2.5
5.2.3
5.1.5
5.1.4
5.1.3
5.1.2
5.1.1
5.1
5.0.3
5.0.2
5.0.1
5.0
4.3.7
4.3.6
4.3.5
4.3.3
4.3.2
4.3.1
4.3
4.2.13
4.2.12
4.2.11
4.2.8
4.2.7
4.2.6
4.2.5
4.2.4
4.2.3
4.2.2
4.2.1
4.2
4.1.10
4.1.9
4.1.7
4.1.6
4.1.5
4.1.4
4.1.3
4.1.2
4.1
4.0.7
4.0.5
4.0.4
4.0.3
4.0
3.5.17
3.5.16
3.5.13
3.5.11
3.5.9
3.5.7
3.5.6
3.5.5
3.5.4
3.5.3
3.5.2
3.5.1
3.5
3.4.9
3.4.8
3.4.7
3.4.6
3.4.5
3.4.3
3.4.2
3.4.1
3.4
3.3.3
3.3.1
3.3
3.2
3.1.2
3.1.1
3.1
3.0.2
3.0.1
2.10.4
2.9.3
2.8.3
2.7.4
2.6.3
2.2.10
2.2.9
2.2.8
2.2.7
2.2.5
2.2.4
2.2.3
2.2.2
2.2.1
2.2
2.1.5
2.1.4
2.1.3
2.1.2
2.1.1
2.1
2.0.3
2.0.2
2.0.1
2.0
1.4.4
1.4.3
1.4.2
1.4.1
1.4
1.3.6
1.3.5
1.2.3
1.1.2
6.2.4
6.3.3
6.7.0
6.3.1
6.2.3
6.4.3
6.6.1
6.5.1
6.4.2
6.4.1
Vulnerabilities (59)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU85440 - Improper input validation CVE-2024-21673 |
CWE-20 | Low | 7.19.18, 8.5.5, 8.7.2 | 16.01.2024 |
SB2024011640 |
||
| #VU85439 - Improper input validation CVE-2024-21672 |
CWE-20 | High | 7.19.18, 8.5.5, 8.7.2 | 16.01.2024 |
SB2024011640 |
||
| #VU85434 - Improper input validation CVE-2023-22526 |
CWE-20 | Medium | 7.19.17, 8.5.5, 8.7.2 | 16.01.2024 |
SB2024011640 |
||
| #VU83896 - Improper Control of Generation of Code ('Code Injection') CVE-2023-22522 |
CWE-94 | High | 7.19.17, 8.4.5, 8.5.4 | 06.12.2023 |
SB2023120608 |
||
| #VU82276 - Allocation of Resources Without Limits or Throttling CVE-2023-5072 |
CWE-770 | Medium | 7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.2 | 20.10.2023 |
SB2023102017 SB2023102018 SB2023113056 and 97 more |
||
| #VU81728 - Resource exhaustion CVE-2023-44487 |
CWE-400 | High | 7.19.16, 7.19.17, 8.3.4, 8.4.5, 8.5.3, 8.5.4, 8.6.1, 8.6.2 | 10.10.2023 |
SB2023101023 SB2023101024 SB2023101037 and 652 more |
||
| #VU80783 - Incorrect Conversion between Numeric Types CVE-2023-3635 |
CWE-681 | Medium | 7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.2 | 14.09.2023 |
SB2023091430 SB2023091528 SB2023100937 and 47 more |
||
| #VU78551 - Improper Control of Generation of Code ('Code Injection') CVE-2023-22508 |
CWE-94 | Medium | 7.19.8, 8.2.0 | 24.07.2023 |
SB2023072410 |
||
| #VU77778 - Improper input validation CVE-2022-29546 |
CWE-20 | Low | 7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.2 | 28.06.2023 |
SB2022050443 SB20230719104 SB20231018117 and 10 more |
||
| #VU77777 - Improper input validation CVE-2022-28366 |
CWE-20 | Low | 7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.1, 8.6.2 | 28.06.2023 |
SB2022042155 SB2023112475 SB2023121271 and 7 more |
||
| #VU70385 - Deserialization of Untrusted Data CVE-2022-1471 |
CWE-502 | High | 7.13.18, 7.19.10, 8.3.1, 8.4.5, 8.5.4 | 15.12.2022 |
SB2022121539 SB2022121540 SB2022121928 and 124 more |
||
| #VU68859 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2022-42252 |
CWE-444 | Medium | 7.19.16 | 31.10.2022 |
SB2022103146 SB2022112324 SB2022112533 and 43 more |
||
| #VU68827 - Improper Control of Generation of Code ('Code Injection') CVE-2022-42890 |
CWE-94 | Low | 7.19.16 | 30.10.2022 |
SB2022103004 SB2022103009 SB2023030742 and 34 more |
||
| #VU68826 - Improper Control of Generation of Code ('Code Injection') CVE-2022-41704 |
CWE-94 | High | 7.19.16 | 30.10.2022 |
SB2022103004 SB2022103009 SB2023030742 and 14 more |
||
| #VU67585 - Server-Side Request Forgery (SSRF) CVE-2022-40146 |
CWE-918 | Medium | 7.19.16 | 22.09.2022 |
SB2022092232 SB2023011763 SB2023011838 and 21 more |
||
| #VU65499 - Improper input validation CVE-2021-31684 |
CWE-20 | Medium | 7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.2 | 20.07.2022 |
SB2022072048 SB2022072056 SB2022112850 and 20 more |
||
| #VU65486 - Improper input validation CVE-2022-24839 |
CWE-20 | Medium | 7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.1, 8.6.2 | 20.07.2022 |
SB2022072038 SB2022102803 SB2022102807 and 31 more |
||
| #VU63958 - Improper Control of Generation of Code ('Code Injection') CVE-2022-26134 |
CWE-94 | Critical | 7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, 7.18.1 | 03.06.2022 |
SB2022060301 |
||
| #VU48979 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2020-25649 |
CWE-611 | Medium | 7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.2 | 03.12.2020 |
SB2020121510 SB2021020321 SB2021042112 and 68 more |
Showing elements 41 - 60 out of 59