Medium severity5.3NVD Advisory· Published May 1, 2023· Updated Jun 17, 2026
CVE-2023-22503
CVE-2023-22503
Description
Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature.
This vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team.
The affected versions are before version 7.13.15, from version 7.14.0 before 7.19.7, and from version 7.20.0 before 8.2.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*range: <7.13.15
- (no CPE)range: <7.13.15, 7.14.0 to <7.19.7, 7.20.0 to <8.2.0
- (no CPE)range: >= 7.20.2
cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*range: <7.13.15
- (no CPE)range: <7.13.15, 7.14.0 to <7.19.7, 7.20.0 to <8.2.0
- (no CPE)range: >= 7.20.2
Patches
Vulnerability mechanics
References
1- jira.atlassian.com/browse/CONFSERVER-82403nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.