ZeroHour
Security Affairspublished ()ingested @securityaffairs

Atlassian fixed critical RCE in older Confluence versions

criticalVulnerabilityimportance 60CVE-2023-22527

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-22527
Unauthenticated OGNL Template Injection RCE in Atlassian Confluence Data Center/Server

Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability (CWE-74) in which attacker-controlled input is evaluated by the application as an OGNL expression. A remote, unauthenticated attacker can trigger the flaw by sending a crafted HTTP request that injects OGNL expressions, which the server then executes. Successful exploitation leads to remote code execution on the host running Confluence, giving the attacker control of the system without any credentials. Any organization running self-hosted Confluence Data Center or Server is potentially affected — the available data does not specify version ranges, so operators should consult Atlassian's advisory — with internet-facing instances at highest risk. Exploitation is active: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-24 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days (100th percentile).

Do: Patch to the fixed release specified in Atlassian's advisory immediately, prioritizing internet-exposed instances, since the flaw is in CISA's KEV with known ransomware use and carries a 100% EPSS. If patching is not immediately possible, apply the vendor's mitigations per the KEV required action — or discontinue/restrict use — for example by limiting unauthenticated access to Confluence from the internet. Review Confluence access and application logs for anomalous unauthenticated requests and indicators of command execution or ransomware activity.

9.8100% KEV ransomware PoC ×2
  • Atlassian Confluence Data Center and Server
largetens of thousands of internet-exposed Confluence instances (order of 10,000–100,000)
Full article249 words · extracted from securityaffairs.com · click to collapse

Atlassian warns of a critical remote code execution issue in Confluence Data Center and Confluence Server that impacts older versions.

Atlassian warns of a critical remote code execution vulnerability, tracked as CVE-2023-22527 (CVSS score 10.0), in Confluence Data Center and Confluence Server that impacts older versions.

The vulnerability is a template injection vulnerability that can allow remote attackers to execute arbitrary code on vulnerable Confluence installs.

The flaw affects Confluence Data Center and Server versions 8.0.x, 8.1.x, 8.2.x, 8.3.x, 8.4.x, and 8.5.0 through 8.5.3. Most recent supported versions of Confluence Data Center and Server are not affected by this issue.

“A template injection vulnerability on out-of-date versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected version. Customers using an affected version must take immediate action.” reads the advisory published by the vendor. “This RCE (Remote Code Execution) vulnerability affects out-of-date Confluence Data Center and Server 8 versions released before Dec. 5, 2023 as well as 8.4.5 which no longer receives backported fixes in accordance with our Security Bug Fix Policy. Atlassian recommends patching to the latest version.”

The company addressed the vulnerability with the release of versions 8.5.4 (LTS), 8.6.0 (Data Center only), and 8.7.1 (Data Center only).

Atlassian recommends customers to install the latest version.

The security bulletin states that there is no known workarounds or mitigation to remediate this vulnerability.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Confluence Data Center)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/157591/security/atlassian-rce-flaw-older-confluence-versions.html