Atlassian Confluence 7.19.x < 7.19.23 / 7.20.x < 8.5.11 / 8.6.x < 8.6.2 / 8.7.x < 8.7.2 / 8.8.x < 8.9.3 (CONFSERVER-98231)
Discription

image
The version of Atlassian Confluence Server running on the remote host is affected by a vulnerability as referenced in the CONFSERVER-98231 advisory. In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component. (CVE-2023-52428) Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version…Read More

Back to Main

Subscribe for the latest news: