Junglewise Threat Intelligence

CVE-2023-22515: Atlassian Confluence Data Center and Server Broken Access Control Vulnerability

CVE-2023-22515 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2023-10-05

Technologies: Atlassian Confluence Data Center, Atlassian Server, Atlassian Confluence Server. Vendors: Atlassian.

Executive brief

A broken access control vulnerability in Atlassian Confluence Data Center and Server allows unauthenticated remote attackers to create unauthorized administrator accounts. This flaw enables full access to affected Confluence instances, though Atlassian Cloud sites are not impacted.

Affected products

  • Atlassian Confluence Data Center
  • Atlassian Confluence Server

Timeline

  • 2023-10-05: disclosed
  • 2023-10-05: advisory
  • 2023-10-05: exploited: Added to CISA KEV catalog on this date.
  • 2023-10-05: kev added

Related threats