ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Atlassian Confluence Hit by New Actively Exploited Zero-Day

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-22515

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-22515
Unauthenticated Broken Access Control in Atlassian Confluence Data Center/Server

Atlassian Confluence Data Center and Server contain a broken access control flaw (CWE-20) in publicly accessible instances that allows unauthenticated remote attackers to create unauthorized Confluence administrator accounts and gain access to the instance; the associated public PoC is titled 'Atlassian Confluence Unauthenticated Remote Code Execution'. The flaw is triggered over the network (CVSS 3.1 9.8, AV:N/AC:L/PR:N/UI:N) against any self-managed Confluence instance reachable from the internet, with no privileges or user interaction required. Attackers who exploit it gain administrator-level control of the Confluence instance, and the public PoC demonstrates this extends to unauthenticated code execution. Only self-managed Confluence Data Center and Server deployments are affected; Atlassian Cloud sites hosted on atlassian.net domains are not vulnerable. Exploitation is confirmed in the wild: CISA added it to the KEV on 2023-10-05 with known ransomware use, EPSS is 99.2%, Atlassian reported a handful of customers were already exploited, and Microsoft warned of nation-state (China-linked) abuse.

Do: Patch all internet-facing Confluence Data Center and Server instances to a fixed release per Atlassian's advisory (specific fixed versions are not listed in this data), or restrict public access/discontinue use per CISA's required action. Audit every affected instance for evidence of compromise, especially unauthorized administrator accounts created through this flaw, and report positive findings to CISA. Treat this as urgent given active exploitation by both nation-state actors and ransomware groups.

9.899% KEV ransomware PoC
  • Atlassian Confluence Data Center
  • Atlassian Confluence Server
large≈ tens of thousands of internet-exposed Confluence Data Center/Server instances (order of ~30,000-50,000)

Indicators of compromiseAll →

TypeIndicatorContext
domainatlassian.nete versions prior to 8.0.0. Confluence sites accessed via an atlassian.net domain are also not vulnerable to this issue. The enterpris
Full article407 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananOct 05, 2023Zero Day / Vulnerability

Atlassian has released fixes to contain an actively exploited critical zero-day flaw impacting publicly accessible Confluence Data Center and Server instances.

The vulnerability, tracked as CVE-2023-22515, is remotely exploitable and allows external attackers to create unauthorized Confluence administrator accounts and access Confluence servers.

It does not impact Confluence versions prior to 8.0.0. Confluence sites accessed via an atlassian.net domain are also not vulnerable to this issue.

The enterprise software services provider said it was made aware of the issue by "a handful of customers." It has been addressed in the following versions of Confluence Data Center and Server -

  • 8.3.3 or later
  • 8.4.3 or later, and
  • 8.5.2 (Long Term Support release) or later

The company, however, did not disclose any further specifics about the nature and scale of the exploitation, or the root cause of the vulnerability.

Customers who are unable to apply the updates are advised to restrict external network access to the affected instances.

"Additionally, you can mitigate known attack vectors for this vulnerability by blocking access to the /setup/* endpoints on Confluence instances," Atlassian said. "This is possible at the network layer or by making the following changes to Confluence configuration files."

The company has also provided the following indicators of compromise (IoCs) to determine if an on-premise instance has been potentially breached -

  • unexpected members of the confluence-administrator group
  • unexpected newly created user accounts
  • requests to /setup/*.action in network access logs
  • presence of /setup/setupadministrator.action in an exception message in atlassian-confluence-security.log in the Confluence home directory

"If it is determined that your Confluence Server/DC instance has been compromised, our advice is to immediately shut down and disconnect the server from the network/Internet," Atlassian said.

"Also, you may want to immediately shut down any other systems which potentially share a user base or have common username/password combinations with the compromised system."

"It's unusual, though not unprecedented, for a privilege escalation vulnerability to carry a critical severity rating," Rapid7's Caitlin Condon said, adding the flaw is "typically more consistent with an authentication bypass or remote code execution chain than a privilege escalation issue by itself."

With flaws in Atlassian Confluence instances widely exploited by threat actors in the past, it's recommended that customers update to a fixed version immediately, or implement appropriate mitigations.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/10/atlassian-confluence-hit-by-newly.html