Executive brief
An improper authorization vulnerability in Atlassian Confluence Data Center and Server allows unauthenticated attackers to reset the instance and create a new administrator account. This can lead to a full loss of confidentiality, integrity, and availability as the attacker gains complete administrative control.
Affected products
- Atlassian Confluence Data Center All versions prior to 7.19.16, 8.3.4, 8.4.4, 8.5.3, and 8.6.0
- Atlassian Confluence Server All versions prior to 7.19.16, 8.3.4, 8.4.4, 8.5.3, and 8.6.0
Timeline
- 2023-11-07: disclosed
- 2023-11-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-11-07: advisory