Junglewise Threat Intelligence

CVE-2023-22518: Atlassian Confluence Data Center and Server Improper Authorization Vulnerability

CVE-2023-22518 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2023-11-07

Executive brief

An improper authorization vulnerability in Atlassian Confluence Data Center and Server allows unauthenticated attackers to reset the instance and create a new administrator account. This can lead to a full loss of confidentiality, integrity, and availability as the attacker gains complete administrative control.

Affected products

  • Atlassian Confluence Data Center All versions prior to 7.19.16, 8.3.4, 8.4.4, 8.5.3, and 8.6.0
  • Atlassian Confluence Server All versions prior to 7.19.16, 8.3.4, 8.4.4, 8.5.3, and 8.6.0

Timeline

  • 2023-11-07: disclosed
  • 2023-11-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-11-07: advisory

Related threats