Vulnerability record · CVE-2015-8399 · published 11 April 2016
CVE-2015-8399: Atlassian Confluence decoratorName parameter configuration file disclosure
Atlassian · Confluence
Atlassian Confluence before 5.8.17 lets remote authenticated users read configuration files through the decoratorName parameter passed to spaces/viewdefaultdecorator.action or admin/viewdefaultdecorator.action. The flaw is an information exposure issue (CWE-200) that leaks server-side configuration content to any logged-in user. It matters because configuration files often hold credentials, connection strings and internal paths that support further attacks.
Description
Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Automated analysis
high priorityThe flaw is easy to reach for any authenticated user, a public exploit exists, and EPSS is very high despite the medium CVSS score.
What it is
Atlassian Confluence before 5.8.17 lets remote authenticated users read configuration files through the decoratorName parameter passed to spaces/viewdefaultdecorator.action or admin/viewdefaultdecorator.action. The flaw is an information exposure issue (CWE-200) that leaks server-side configuration content to any logged-in user. It matters because configuration files often hold credentials, connection strings and internal paths that support further attacks.
Impact
An attacker with a valid low-privileged account gains read access to Confluence configuration files, exposing sensitive settings and potentially credentials. The direct impact is confidentiality loss only; no integrity or availability effect is described.
Attack surface
Reached over the network via HTTP requests to the two named Confluence actions with a crafted decoratorName parameter. Authentication is required (PR:L) and no user interaction is needed (UI:N), so any logged-in user can attempt it.
Exploitation
Not listed in CISA KEV, but a public Exploit-DB entry (39170) exists and EPSS shows a 30-day probability of about 0.60 (99th percentile), indicating high observed likelihood of exploitation activity.
What to do
- Upgrade Confluence to 5.8.17 or later, which fixes the flaw.
- If immediate upgrade is not possible, restrict access to the viewdefaultdecorator.action endpoints and review who holds authenticated accounts.
- Apply least privilege to Confluence accounts and remove or disable unused user accounts.
- Monitor and rotate any credentials or secrets that may have been stored in exposed configuration files.
- Review web server and proxy logs for requests containing decoratorName parameters against the affected actions.
Detection
- Search HTTP access logs for requests to spaces/viewdefaultdecorator.action or admin/viewdefaultdecorator.action with a decoratorName parameter.
- Alert on decoratorName values containing path traversal sequences or references to configuration file names.
- Correlate these requests with authenticated sessions and flag unusual or repeated attempts from a single account.
- Review Confluence audit logs for access to the affected actions by non-administrative users.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-8399 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-8399), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.