Atlassian Confluence data-wiping vulnerability exploited
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-22518 | Improper Authorization in Atlassian Confluence Data Center and Server Atlassian Confluence Data Center and Server contain an improper authorization flaw (CWE-863) that can be triggered by an unauthenticated attacker sending crafted requests to a vulnerable instance. Successful exploitation gives the attacker control over the instance and can cause significant data loss, such as wiping or resetting the Confluence site, but there is no confidentiality impact because no data can be exfiltrated. Any organization running a self-managed Confluence Data Center or Server deployment is in scope. Exploitation is active: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-11-07 with ransomware use noted, and EPSS assigns it a 100% probability of exploitation within 30 days. No public proof-of-concept is known, but ransomware operators are already using the flaw in the wild. Do: Upgrade every Confluence Data Center and Server instance to the patched release for your branch listed in Atlassian's advisory, per the CISA KEV required action (apply vendor mitigations or discontinue use). In the interim, restrict internet access to Confluence and check for signs of compromise such as unexpected instance resets, missing data, or ransom notes; restore from backups if data loss is detected. | 9.8 | 100% | KEV ransomware PoC |
| large≈70,000+ internet-exposed Confluence instances per public scans, likely 100k+ total self-managed installations |
Full article472 words · extracted from helpnetsecurity.com · click to collapse
Threat actors are trying to exploit CVE-2023-22518, a critical Atlassian Confluence flaw that allows unauthenticated attackers to reset vulnerable instances’ database, Greynoise is observing.
The Shadowserver Foundation has also seen 30+ IP addresses testing for the flaw in internet-facing Confluence installations.
From security updates to active exploitation
Atlassian released security updates for CVE-2023-22518 on October 31 and urged customers to upgrade quickly, even though there was no indication that the vulnerability was being targeted.
“Instances accessible to the public internet, including those with user authentication, should be restricted from external network access until you can patch,” Atlassian advised.
On November 2, Atlassian CISO Bala Sathiamurthy confirmed that there was “publicly posted critical information about the vulnerability which increases risk of exploitation.” The day after (i.e., last Friday), the company confirmed that they received a customer report of an active exploit.
At least one PoC exploit for CVE-2023-22518 have since been published on GitHub.
Mitigation and remediation
While the vulnerability does not allow attackers to exfiltrate data, Atlassian says that if an instance has been compromised customers might experience significant data loss, and might not be able to connect to their instance’s URL or to properly authenticate to the instance anymore.
“If able to authenticate, the instance won’t have any content created and/or different content than it originally had,” the company warned.
Customers might also notice suspicious files and/or directories created under the /temp folder, and can search for indicators of compromise in their Confluence logs.
“Since the attack consists of resetting the instance’s content, recovering from a previous backup is the only way of recovering your data. If you believe your Confluence instance was compromised, contact Atlassian Support as Atlassian assistance is required to recover your instance,” the company added.
Customers lucky enough not to be hit should update their Confluence installation quickly, or back up their instance’s data and remove their instance from the public internet to minimize risk of exploitation.
UPDATE (November 8, 2023, 05:40 a.m. ET):
Atlassian has updated CVE-2023-22518’s CVSS score from 9.1 to 10 and added new indicators of compromise to the security advisory, since they now know that the vulnerability allows attackers to reset the database of vulnerable instances AND to create a Confluence instance administrator account.
“Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to a full loss of confidentiality, integrity and availability,” the company admitted.
Rapid7’s incident responders and Huntress researchers have also observed threat actors exploiting the flaw to deliver Cerber ransomware on exploited Confluence servers.
“The speed at which this campaign unfolded, with only a few days between the release of a patch and active, in-the-wild exploitation, emphasizes how quickly such adversaries work to identify and take advantage of distribution mechanisms for their wares,” Huntress researchers noted.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/11/06/cve-2023-22518-exploit/