The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.
| Software | From | Fixed in |
|---|---|---|
| atlassian / confluence_server | - | 5.8.6 |
| atlassian / confluence_data_center | - | 5.8.6 |