CVE-2023-22515: critical vulnerability in Atlassian Confluence Data Center
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Check all affected Confluence instances for evidence of compromise per vendor instructions and report any positive findings to CISA.
A critical vulnerability in Confluence Data Center and Server allows attackers to create unauthorized administrator accounts on publicly exposed instances, giving them full control over the system.
An improper input validation vulnerability (CWE-20) in Confluence Data Center and Server enables unauthenticated remote attackers to create malicious administrator accounts via a publicly accessible instance, bypassing authentication controls and leading to complete system compromise. Confluence Cloud instances are not affected.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.