cbcvebase.
CVE-2023-22515
published 2023-10-04

CVE-2023-22515: Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in…

PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2023-10-13
Exploited in the wild
EPSS
99.16%
99.9th percentile
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center>= 8.0.0 < 8.3.38.3.3
atlassianconfluence_data_center>= 8.4.0 < 8.4.38.4.3
atlassianconfluence_data_center>= 8.5.0 < 8.5.28.5.2
atlassianconfluence_server
atlassianconfluence_server
atlassianconfluence_server

Detection & IOCsextracted from sources · hover to see the quote

url/server-info.action?bootstrapStatusProvider.applicationConfig.setupComplete=false
path/setup/setupadministrator.action
commandbootstrapStatusProvider.applicationConfig.setupComplete=false
  • Detect HTTP GET/POST requests to /server-info.action containing the parameter 'bootstrapStatusProvider.applicationConfig.setupComplete=false' — this is Stage 1 of the exploit chain used to flip the setup completion status and unlock the administrator setup endpoint.
  • Monitor for unauthenticated POST requests to /setup/setupadministrator.action — Stage 2 of the exploit chain attempts to register an attacker-controlled administrator account via this endpoint.
  • Audit Confluence for newly created administrator accounts, especially those created without a corresponding legitimate provisioning event — exploitation results in unauthorized admin account creation.
  • The vulnerability was exploited as a zero-day starting September 14 by threat group tracked as Storm-0062 (also known as DarkShadow and Oro0lxy); threat hunting should include activity from this group on Confluence servers from that date forward.
  • Check Point IPS signature 'Atlassian Confluence Authentication Bypass (CVE-2023-22515)' can be used for network-level detection of exploitation attempts.
  • Qualys WAS QID 150745 is an intrusive detection that exploits vulnerable servers by sending requests to the vulnerable endpoint — use QID 150725 for non-intrusive version-based detection of CVE-2023-22515.
  • Threat actors maintained persistence even after patching was applied — post-patch forensic review of administrator accounts and active sessions is essential.
  • ·Atlassian Cloud (atlassian.net-hosted) instances are NOT affected by CVE-2023-22515 — only on-premise Confluence Data Center and Server deployments are vulnerable.
  • ·Only Confluence versions 8.0.0 through 8.5.1 are affected; fixed versions are 8.3.3, 8.4.3, and 8.5.2 or later.
  • ·Internet-facing (publicly accessible) Confluence instances are at highest risk as the vulnerability is exploitable anonymously without authentication.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.