https://jira.atlassian.com/browse/CONFSERVER-59358
This is the only information I have to support this vulnerability, but it doesn't speak to the product or vulnerability. I can not provide updates to my user community without justification. Can you assist, please?
Hi Willie, welcome to the Community!
Following the CVE number you posted out to MITRE, we see this publicly available vulnerability information:
The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before version 6.15.5 allows remote attackers to achieve stored cross-site- scripting (SXSS) via a malicious attachment with a modified `mimeType` parameter.
The bugfix version for 6.15 has been beyond 6.15.5 for some time (6.15.6 was released 24 June 2019) - if someone is running an affected version of 6.15.x, it should be relatively straightforward for them to upgrade in that minor version line.
Is there additional information you need here, or will the affected versions suffice for your user community?
Thanks,Daniel | Atlassian Team
Thank you for your prompt response, Daniel. The information helps, but could you direct me to the documentation that covers CVE-2019-20102 and the patch link to download for the most current version. Thanks again.
https://jira.atlassian.com/browse/CONFSERVER-59358 to me did not really inform the vulnerability, but I could be misunderstanding. Looking for any additional information for clarity, thanks
Nevermind guys, I appreciate all your assistance. My team was able to find the necessary information to provide to our customers.
It looks like you're new here. Sign in or register to get started.