← Vulnerability feed

Vulnerability record · CVE-2015-8399 · published 11 April 2016

CVE-2015-8399: Atlassian Confluence decoratorName parameter configuration file disclosure

Atlassian · Confluence

Atlassian Confluence before 5.8.17 lets remote authenticated users read configuration files through the decoratorName parameter passed to spaces/viewdefaultdecorator.action or admin/viewdefaultdecorator.action. The flaw is an information exposure issue (CWE-200) that leaks server-side configuration content to any logged-in user. It matters because configuration files often hold credentials, connection strings and internal paths that support further attacks.

4.3 CVSS 3.0 Medium EPSS 60% · top 0.9% CWE-200 · Information exposure
4.3CVSS 3.0 base score, v2 4.0
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityThe flaw is easy to reach for any authenticated user, a public exploit exists, and EPSS is very high despite the medium CVSS score.

What it is

Atlassian Confluence before 5.8.17 lets remote authenticated users read configuration files through the decoratorName parameter passed to spaces/viewdefaultdecorator.action or admin/viewdefaultdecorator.action. The flaw is an information exposure issue (CWE-200) that leaks server-side configuration content to any logged-in user. It matters because configuration files often hold credentials, connection strings and internal paths that support further attacks.

Impact

An attacker with a valid low-privileged account gains read access to Confluence configuration files, exposing sensitive settings and potentially credentials. The direct impact is confidentiality loss only; no integrity or availability effect is described.

Attack surface

Reached over the network via HTTP requests to the two named Confluence actions with a crafted decoratorName parameter. Authentication is required (PR:L) and no user interaction is needed (UI:N), so any logged-in user can attempt it.

Exploitation

Not listed in CISA KEV, but a public Exploit-DB entry (39170) exists and EPSS shows a 30-day probability of about 0.60 (99th percentile), indicating high observed likelihood of exploitation activity.

What to do

  • Upgrade Confluence to 5.8.17 or later, which fixes the flaw.
  • If immediate upgrade is not possible, restrict access to the viewdefaultdecorator.action endpoints and review who holds authenticated accounts.
  • Apply least privilege to Confluence accounts and remove or disable unused user accounts.
  • Monitor and rotate any credentials or secrets that may have been stored in exposed configuration files.
  • Review web server and proxy logs for requests containing decoratorName parameters against the affected actions.

Detection

  • Search HTTP access logs for requests to spaces/viewdefaultdecorator.action or admin/viewdefaultdecorator.action with a decoratorName parameter.
  • Alert on decoratorName values containing path traversal sequences or references to configuration file names.
  • Correlate these requests with authenticated sessions and flag unusual or repeated attempts from a single account.
  • Review Confluence audit logs for access to the affected actions by non-administrative users.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-8399 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-3395Atlassian confluence server-side request forgery (ssrf) vulnerabilityThe WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.…EPSS 6.7%9.1CVE-2012-2926Atlassian JIRA and related products XML parser file read and DoSMultiple Atlassian products (JIRA, Confluence, FishEye, Crucible, Bamboo, Crowd) fail to properly restrict the capabilities of third-party XML parser…EPSS 66%analysed8.8CVE-2019-3394Atlassian confluence path traversal vulnerabilityThere was a local file disclosure vulnerability in Confluence Server and Confluence Data Center via page exporting. An attacker with permission to ed…EPSS 11%7.8CVE-2019-20406Atlassian confluence uncontrolled search path element vulnerabilityThe usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows …EPSS 0.48%6.5CVE-2019-15006Atlassian confluence improper control of dynamically-managed code vulnerabilityThere was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center. This pl…EPSS 1.9%6.1CVE-2017-18085Atlassian confluence cross-site scripting vulnerabilityThe viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript …EPSS 0.81%6.1CVE-2017-18086Atlassian confluence cross-site scripting vulnerabilityVarious resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site …EPSS 0.81%6.1CVE-2017-16856Atlassian confluence cross-site scripting vulnerabilityThe RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripti…EPSS 0.81%

Source: NIST National Vulnerability Database (record CVE-2015-8399), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.