ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Critical Atlassian Bug Exploited in Ransomware Attacks

criticalRansomware exploited in the wildimportance 60CVE-2023-22518CVE-2023-22515

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-22515
Unauthenticated Broken Access Control in Atlassian Confluence Data Center/Server

Atlassian Confluence Data Center and Server contain a broken access control flaw (CWE-20) in publicly accessible instances that allows unauthenticated remote attackers to create unauthorized Confluence administrator accounts and gain access to the instance; the associated public PoC is titled 'Atlassian Confluence Unauthenticated Remote Code Execution'. The flaw is triggered over the network (CVSS 3.1 9.8, AV:N/AC:L/PR:N/UI:N) against any self-managed Confluence instance reachable from the internet, with no privileges or user interaction required. Attackers who exploit it gain administrator-level control of the Confluence instance, and the public PoC demonstrates this extends to unauthenticated code execution. Only self-managed Confluence Data Center and Server deployments are affected; Atlassian Cloud sites hosted on atlassian.net domains are not vulnerable. Exploitation is confirmed in the wild: CISA added it to the KEV on 2023-10-05 with known ransomware use, EPSS is 99.2%, Atlassian reported a handful of customers were already exploited, and Microsoft warned of nation-state (China-linked) abuse.

Do: Patch all internet-facing Confluence Data Center and Server instances to a fixed release per Atlassian's advisory (specific fixed versions are not listed in this data), or restrict public access/discontinue use per CISA's required action. Audit every affected instance for evidence of compromise, especially unauthorized administrator accounts created through this flaw, and report positive findings to CISA. Treat this as urgent given active exploitation by both nation-state actors and ransomware groups.

9.899% KEV ransomware PoC
  • Atlassian Confluence Data Center
  • Atlassian Confluence Server
large≈ tens of thousands of internet-exposed Confluence Data Center/Server instances (order of ~30,000-50,000)
CVE-2023-22518
Improper Authorization in Atlassian Confluence Data Center and Server

Atlassian Confluence Data Center and Server contain an improper authorization flaw (CWE-863) that can be triggered by an unauthenticated attacker sending crafted requests to a vulnerable instance. Successful exploitation gives the attacker control over the instance and can cause significant data loss, such as wiping or resetting the Confluence site, but there is no confidentiality impact because no data can be exfiltrated. Any organization running a self-managed Confluence Data Center or Server deployment is in scope. Exploitation is active: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-11-07 with ransomware use noted, and EPSS assigns it a 100% probability of exploitation within 30 days. No public proof-of-concept is known, but ransomware operators are already using the flaw in the wild.

Do: Upgrade every Confluence Data Center and Server instance to the patched release for your branch listed in Atlassian's advisory, per the CISA KEV required action (apply vendor mitigations or discontinue use). In the interim, restrict internet access to Confluence and check for signs of compromise such as unexpected instance resets, missing data, or ransom notes; restore from backups if data loss is detected.

9.8100% KEV ransomware PoC
  • Atlassian Confluence Data Center and Server
large≈70,000+ internet-exposed Confluence instances per public scans, likely 100k+ total self-managed installations

Indicators of compromiseAll →

TypeIndicatorContext
domainshutterstock.coms, although not exfiltrate it. Image credit: T. Schneider / Shutterstock.com
Full article298 words · extracted from infosecurity-magazine.com · click to collapse

Security researchers have warned that threat actors are already exploiting a critical Atlassian vulnerability for which a public exploit was found just last week.

The Australian software developer said last Thursday that it had discovered “publicly posted critical information” about CVE-2023-22518, which has a CVSS score of 9.1 and impacts all versions of Atlassian Confluence Data Center and Server.

Then over the weekend, Rapid7 said it had observed exploitation of the vulnerability in “multiple customer environments,” as well as attacks using an older flaw, CVE-2023-22515, which is a critical broken access control bug discovered on October 4.

The security vendor explained that the process execution chain was consistent across multiple environments, hinting at mass exploitation of vulnerable internet-facing Atlassian Confluence servers.

“After the initial enumeration activity, the adversary executed Base64 commands to spawn follow-on commands via python2 or python3,” it added in a blog post.

“In multiple attack chains, Rapid7 observed post-exploitation command execution to download a malicious payload hosted at 193.43.72[.]11 and/or 193.176.179[.]41, which, if successful, led to single-system Cerber ransomware deployment on the exploited Confluence server.”

Read more on Atlassian threats: Atlassian Patches Critical Authentication Flaw in Jira Software

For its part, Atlassian updated its own security advisory, nudging the CVSS score of CVE-2023-22518 up to 10.0 “due to the change in the scope of the attack.”

Customers are urged to update to the latest version of the product as soon as possible, although Atlassian Cloud users are not affected.

According to the non-profit ShadowServer, there are over 24,000 Confluence servers currently online, although it’s not clear how many remain on vulnerable software versions.

Atlassian initially warned that CVE-2023-22518 could allow an attacker to wipe any data they find in affected Confluence environments, although not exfiltrate it.

Image credit: T. Schneider / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/critical-atlassian-bug-ransomware/