← All CVEs

CVE-2023-22515

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Check all affected Confluence instances for evidence of compromise per vendor instructions and report any positive findings to CISA.

Added 2023-10-05Remediation due 2023-10-13

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

9.8
CVSS
99.2%
EPSS (exploit prob.)
100th
EPSS percentile
2023-10-04
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
atlassianconfluence_data_center>= 8.0.0, < 8.3.3
atlassianconfluence_data_center>= 8.4.0, < 8.4.3
atlassianconfluence_data_center>= 8.5.0, < 8.5.2
atlassianconfluence_server>= 8.0.0, < 8.3.3
atlassianconfluence_server>= 8.4.0, < 8.4.3
atlassianconfluence_server>= 8.5.0, < 8.5.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-22515