Security News > 2024 > January > Atlassian reveals critical Confluence RCE flaw, urges “immediate action” (CVE-2023-22527)

Atlassian reveals critical Confluence RCE flaw, urges “immediate action” (CVE-2023-22527)
2024-01-16 17:37

Atlassian has patched a critical vulnerability in Confluence Data Center and Confluence Server that could lead to remote code execution.

Atlassian hasn't mentioned whether the vulnerability is being actively exploited, but has said that customers "Must take immediate action to protect their Confluence instances."

CVE-2023-22527 is a template injection vulnerability that allows an unauthenticated attacker to achieve RCE on an affected version of Confluence Data Center and Confluence Server: 8.0.x, 8.1.x, 8.2.x, 8.3.x, 8.4.x, and 8.5.0-8.5.3.

Atlassian Cloud instances are not affected by this vulnerability, and neither is Confluence version 7.19.x. Additional advice for customers.

Vulnerable Confluence instances have been preferred targets of various threat actors over the years.

"If the Confluence instance cannot be accessed from the internet the risk of exploitation is reduced, but not completely mitigated," the company added, and again "Strongly recommended" upgrading to the latest version available.


News URL

https://www.helpnetsecurity.com/2024/01/16/cve-2023-22527/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2024-01-16 CVE-2023-22527 Injection vulnerability in Atlassian Confluence Data Center and Confluence Server
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance.
network
low complexity
atlassian CWE-74
critical
9.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Atlassian 58 56 291 41 34 422