AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-29448

MEDIUM · CVSS 5.3 EPSS 2.33%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-02-22 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2020-29448
Severity
MEDIUM
CVSS
5.3
EPSS
2.33%

Original NVD Description

The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and from 7.5.0 before 7.8.3 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.