Atlassian patches critical Confluence bug, urges for immediate action (CVE-2023-22518)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-22515 | Unauthenticated Broken Access Control in Atlassian Confluence Data Center/Server Atlassian Confluence Data Center and Server contain a broken access control flaw (CWE-20) in publicly accessible instances that allows unauthenticated remote attackers to create unauthorized Confluence administrator accounts and gain access to the instance; the associated public PoC is titled 'Atlassian Confluence Unauthenticated Remote Code Execution'. The flaw is triggered over the network (CVSS 3.1 9.8, AV:N/AC:L/PR:N/UI:N) against any self-managed Confluence instance reachable from the internet, with no privileges or user interaction required. Attackers who exploit it gain administrator-level control of the Confluence instance, and the public PoC demonstrates this extends to unauthenticated code execution. Only self-managed Confluence Data Center and Server deployments are affected; Atlassian Cloud sites hosted on atlassian.net domains are not vulnerable. Exploitation is confirmed in the wild: CISA added it to the KEV on 2023-10-05 with known ransomware use, EPSS is 99.2%, Atlassian reported a handful of customers were already exploited, and Microsoft warned of nation-state (China-linked) abuse. Do: Patch all internet-facing Confluence Data Center and Server instances to a fixed release per Atlassian's advisory (specific fixed versions are not listed in this data), or restrict public access/discontinue use per CISA's required action. Audit every affected instance for evidence of compromise, especially unauthorized administrator accounts created through this flaw, and report positive findings to CISA. Treat this as urgent given active exploitation by both nation-state actors and ransomware groups. | 9.8 | 99% | KEV ransomware PoC |
| large≈ tens of thousands of internet-exposed Confluence Data Center/Server instances (order of ~30,000-50,000) | |
| CVE-2023-22518 | Improper Authorization in Atlassian Confluence Data Center and Server Atlassian Confluence Data Center and Server contain an improper authorization flaw (CWE-863) that can be triggered by an unauthenticated attacker sending crafted requests to a vulnerable instance. Successful exploitation gives the attacker control over the instance and can cause significant data loss, such as wiping or resetting the Confluence site, but there is no confidentiality impact because no data can be exfiltrated. Any organization running a self-managed Confluence Data Center or Server deployment is in scope. Exploitation is active: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-11-07 with ransomware use noted, and EPSS assigns it a 100% probability of exploitation within 30 days. No public proof-of-concept is known, but ransomware operators are already using the flaw in the wild. Do: Upgrade every Confluence Data Center and Server instance to the patched release for your branch listed in Atlassian's advisory, per the CISA KEV required action (apply vendor mitigations or discontinue use). In the interim, restrict internet access to Confluence and check for signs of compromise such as unexpected instance resets, missing data, or ransom notes; restore from backups if data loss is detected. | 9.8 | 100% | KEV ransomware PoC |
| large≈70,000+ internet-exposed Confluence instances per public scans, likely 100k+ total self-managed installations |
Full article342 words · extracted from helpnetsecurity.com · click to collapse
Atlassian is urging enterprise administrators to update their on-premises Confluence Data Center and Server installations quickly to plug a critical security vulnerability (CVE-2023-22518) that could lead to “significant data loss if exploited by an unauthenticated attacker.”

About CVE-2023-22518
CVE-2023-22518 has been categorized as an improper authorization vulnerability, but no other details have been shared by the Australian software maker.
It affects all versions of Confluence Data Center and Server before versions 7.19.16, 8.3.4, 8.4.4, 8.5.3 and 8.6.1.
“Versions outside of the support window (i.e. versions that have reached End of Life) may also be affected, so Atlassian recommends you upgrade to a fixed LTS version or later,” the company said.
“Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.”
Even though “there are no reports of active exploitation at this time”, Atlassian says that all publicly accessible on-prem instances should be upgraded immediately.
Admins that can’t patch at this time are advised to back up their instance and temporarility remove it from the internet.
“Instances accessible to the public internet, including those with user authentication, should be restricted from external network access until you can patch,” the company added.
Vulnerable Atlassian Confluence instances are often targeted by attackers
Atlassian pushed out critical patches for Confluence Data Center and Server earlier this month, when it fixed CVE-2023-22515, a broken access control zero-day flaw that was being exploited by a state-backed threat actor.
0-day and n-day vulnerabilities in Confluence Data Center and Server are regularly taken advantage of by a variety of attackers.
UPDATE (November 3, 2023, 05:00 a.m. ET):
“As part of Atlassian’s ongoing monitoring of this CVE, we observed publicly posted critical information about the vulnerability which increases risk of exploitation,” Atlassian CISO Bala Sathiamurthy shared on Thursday.
“There are still no reports of an active exploit, though customers must take immediate action to protect their instances. If you already applied the patch, no further action is required.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/10/31/cve-2023-22518/