AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-9505

MEDIUM · CVSS 4.3 EPSS 1.26%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-06-15 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2017-9505
Severity
MEDIUM
CVSS
4.3
EPSS
1.26%

Original NVD Description

Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of comments, for comments added to a page after they started watching it even if they do not have permission to view the page itself.