CVE-2023-22527
published 2024-01-16CVE-2023-22527: A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected…
PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2024-02-14
Exploited in the wild
EPSS
99.98%
100.0th percentile
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action.
Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | >= 8.0.0 < 8.5.4 | 8.5.4 |
| atlassian | confluence_server | — | — |
| atlassian | confluence_server | — | — |
| atlassian | confluence_server | — | — |
| atlassian | confluence_server | — | — |
| atlassian | confluence_server | — | — |
| atlassian | confluence_server | — | — |
| atlassian | confluence_server | — | — |
| atlassian | confluence_server | — | — |
| atlassian | confluence_server | — | — |
| atlassian | confluence_server | >= 8.0.0 < 8.5.4 | 8.5.4 |
Detection & IOCsextracted from sources · hover to see the quote
command#request.get(.KEY_velocity.struts2.context).internalGet(ognl).findValue(#parameters.poc[0],{})&[email protected]@getResponse().setHeader('Cmd-Ret',(new freemarker.template.utility.Execute()).exec({"id"}))↗
- →Monitor HTTP requests targeting the vulnerable endpoint /confluence/template/aui/text-inline.vm for OGNL/FreeMarker injection patterns in the 'label' parameter. ↗
- →Detect exploit payloads containing the string '.KEY_velocity.struts2.context' or '.freemarker.TemplateModel' in HTTP request bodies to Confluence endpoints. ↗
- →Detect cron job creation under names 'whoami', 'nginx', or 'apache' in /etc/init.d, /etc/cron.hourly, or /etc/cron.d as post-exploitation persistence indicators. ↗
- →Apply Trend Micro DPI/DDI rule references for network-level detection of CVE-2023-22527 exploit traffic. ↗
- ·The vulnerable endpoint /confluence/template/aui/text-inline.vm has been removed in patched versions; its presence on a server confirms an unpatched instance. ↗
- ·There are no known workarounds for CVE-2023-22527; patching to 8.5.4+ (Server/DC) or 8.6.0+/8.7.1+ (DC only) is the only remediation. ↗
- ·The attacker's script actively kills known security/monitoring agents (Alibaba Cloud Shield, Tencent Cloud) and clears logs/bash history, reducing forensic visibility on compromised hosts. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Atlassian Confluence Data Center and Server Template Injection Vulnerability
cisa·2024-01-24·CVSS 9.8
CVE-2023-22527 [CRITICAL] CWE-74 Atlassian Confluence Data Center and Server Template Injection Vulnerability
Vulnerability: Atlassian Confluence Data Center and Server Template Injection Vulnerability
Affected: Atlassian Confluence Data Center and Server
Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html; https://nvd.nist.gov/vuln/detail/CVE-2023-22527
Remediation Due Date: 2024-02-14
Atlassian
CVE-2023-22527 - RCE (Remote Code Execution) Vulnerability in Out-of-Date Versions of Confluence Data Center and Server
vendor_atlassian·CVSS 9.8
CVE-2023-22527 [CRITICAL] CVE-2023-22527 - RCE (Remote Code Execution) Vulnerability in Out-of-Date Versions of Confluence Data Center and Server
CVE-2023-22527 - RCE (Remote Code Execution) Vulnerability in Out-of-Date Versions of Confluence Data Center and Server
CVE-2023-22527 - RCE (Remote Code Execution) Vulnerability in Out-of-Date Versions of Confluence Data Center and Server
CVE: CVE-2023-22527
Affected products: Confluence Data Center
GHSA
GHSA-w64x-j9r3-q79q: Summary of Vulnerability
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker
ghsa_unreviewed·2024-01-16
CVE-2023-22527 [CRITICAL] CWE-74 GHSA-w64x-j9r3-q79q: Summary of Vulnerability
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker
Summary of Vulnerability
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action.
Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.
See “What You Need to Do” for detailed instructions.
{panel:bgColor=#deebff}
Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed v
VulnCheck
Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
vulncheck·2023·CVSS 9.8
CVE-2023-22515 [CRITICAL] Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.
Affected: Atlassian Confluence Server and Data Center
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Check all affected Confluence instances for evidence of compromise per vendor instructions and report any positive findings to CISA.
Known Ransomware Campaign Use: Known
Exploitation References: https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html;
VulnCheck
Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
vulncheck·2023·CVSS 9.8
CVE-2023-22518 [CRITICAL] CWE-863 Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.
Affected: Atlassian Confluence Server and Data Center
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.vulncheck.com/v3/index/sans-dshield?cve=CVE-2023-22518; https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-confluence-serve
VulnCheck
Atlassian Confluence Data Center and Server Template Injection Vulnerability
vulncheck·2023·CVSS 9.8
CVE-2023-22527 [CRITICAL] CWE-74 Atlassian Confluence Data Center and Server Template Injection Vulnerability
Atlassian Confluence Data Center and Server Template Injection Vulnerability
Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.
Affected: Atlassian Confluence Server and Data Center
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.rapid7.com/blog/post/2024/01/19/etr-critical-cves-in-outdated-versions-of-atlassian-confluence-and-vmware-vcenter-server/; https://twitter.com/TheDFIRReport/status/1749066611678466205; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2024-01-22&host_type=src&vulnerability=cve-2023-22527
VulnCheck
Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability
vulncheck·2022·CVSS 9.8
CVE-2022-26134 [CRITICAL] CWE-917 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability
Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability
Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.
Affected: Atlassian Confluence Server and Data Center
Required Action: Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.countercraftsec.com/blog/active-
VulnCheck
Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability
vulncheck·2021·CVSS 9.8
CVE-2021-26084 [CRITICAL] CWE-917 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability
Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability
Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.
Affected: Atlassian Confluence Server and Data Center
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.lacework.com/blog/muhstik-takes-aim-at-confluence-cve-2021-26084/; https://cybersecurityworks.com/blog/vulnerabilities/cve-2021-26084-patch-the-confluence-servers-now.html; https://news.sophos.com/en-us/2021/10/04/atom-silo-ransomware-actors-use-confluence-exploit-dll-side-load-for-stealthy-attack/; https://www.lacework.co
VulnCheck
Apache Log4j2 Remote Code Execution Vulnerability
vulncheck·2021·CVSS 10.0
CVE-2021-44228 [CRITICAL] CWE-20 Apache Log4j2 Remote Code Execution Vulnerability
Apache Log4j2 Remote Code Execution Vulnerability
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
Affected: Apache Log4j2
Required Action: For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.
Known Ransomware Campaign Use: Known
Exploitation References: https://cisa.gov/news-events/cybersecurity-advisories/aa21-336a; https://api.vulncheck.com/v3/index/sans-dshield?cve=
Suricata
ET EXPLOIT Atlassian Confluence RCE Attempt Observed (CVE-2023-22527) M2
suricata·2024-01-29·CVSS 9.8
CVE-2023-22527 [CRITICAL] ET EXPLOIT Atlassian Confluence RCE Attempt Observed (CVE-2023-22527) M2
ET EXPLOIT Atlassian Confluence RCE Attempt Observed (CVE-2023-22527) M2
Rule: alert http $EXTERNAL_NET any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Atlassian Confluence RCE Attempt Observed (CVE-2023-22527) M2"; flow:established,to_server; http.method; content:"POST"; http.uri; content:".vm"; endswith; http.request_body; content:".KEY_velocity.struts2"; fast_pattern; content:"%7b"; distance:0; content:"%7d"; distance:0; reference:cve,2023-22527; classtype:attempted-admin; sid:2050543; rev:2; metadata:affected_product Atlassian_Confluence, attack_target Server, created_at 2024_01_29, cve CVE_2023_22527, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2024_11_22, mitre_tactic_id TA00
Suricata
ET EXPLOIT Atlassian Confluence RCE Attempt Observed (CVE-2023-22527) M1
suricata·2024-01-23·CVSS 9.8
CVE-2023-22527 [CRITICAL] ET EXPLOIT Atlassian Confluence RCE Attempt Observed (CVE-2023-22527) M1
ET EXPLOIT Atlassian Confluence RCE Attempt Observed (CVE-2023-22527) M1
Rule: alert http $EXTERNAL_NET any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Atlassian Confluence RCE Attempt Observed (CVE-2023-22527) M1"; flow:established,to_server; http.method; content:"POST"; http.uri; content:".vm"; endswith; http.request_body; content:".KEY_velocity.struts2"; fast_pattern; content:"|7b|"; distance:0; content:"|7d|"; distance:0; reference:cve,2023-22527; classtype:attempted-admin; sid:2050340; rev:1; metadata:affected_product Atlassian_Confluence, attack_target Server, created_at 2024_01_23, cve CVE_2023_22527, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2024_01_23, mitre_tactic_id TA0001, mitre_tactic_na
Nuclei
Atlassian Confluence - Remote Code Execution
nuclei·CVSS 9.8
CVE-2023-22527 [CRITICAL] Atlassian Confluence - Remote Code Execution
Atlassian Confluence - Remote Code Execution
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action.
Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.
Template:
id: CVE-2023-22527
info:
name: Atlassian Confluence - Remote Code Execution
author: iamnooob,rootxharsh,pdresearch
severity: critical
description
Metasploit
Atlassian Confluence SSTI Injection
metasploit
Atlassian Confluence SSTI Injection
Atlassian Confluence SSTI Injection
This module exploits an SSTI injection in Atlassian Confluence servers. A specially crafted HTTP request uses the injection to evaluate an OGNL expression resulting in OS command execution. Versions 8.5.0 through 8.5.3 and 8.0 to 8.4 are known to be vulnerable.
Dfir Report
Another Confluence Bites the Dust: Falling to ELPACO-team Ransomware
blogs_dfir_report·2025-05-19·CVSS 9.8
[CRITICAL] Another Confluence Bites the Dust: Falling to ELPACO-team Ransomware
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion Read More
- dragonforce Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs Read More
Services Overview
Threat Hunting
-
Integration
CTI Program Advisory
Incident Response Playbook
About us
Contact Us
Collaboration
Careers
Analysts
Access DFIR Labs
Get in Touch
Public Reports
Products Overview
Threat intel Overview
Threat Feed
Private DFIR Reports
All Intel
Active Defense
DFIR Labs
Case Artifacts
Detection Pack
AI Training Ground
Service Overview
Threat Hunting
Integration
CTI Program Advisory
Incident Response Playbook
Company Overview
About us
Contact Us
Careers
Analyst
SQL Brute Force Leads to BlueSky Ransomware
From OneNote to RansomNote: An Ice Col
Sentinelone
Prioritizing CVEs in the Cloud
blogs_sentinelone·2025-05-15
Prioritizing CVEs in the Cloud
## Foreword & Guest Bio
As part of this ongoing series, SentinelOne is excited to present a series of guest blogs from cloud security experts covering their views on cloud security best practices. Following on from blogs from Teri Radichel who focused on what AWS security gotchas to avoid and how to address the risk of faulty logic. We now have Rami McCarthy providing his view on cloud CVEs, and approach to vulnerability prioritization.
Rami is a self-proclaimed “security wonk”. Most recently, he helped build the Infrastructure Security program at Figma. Before that, he worked as a security consultant and helped scale security for a health-tech unicorn. He writes extensively about security over at ramimac.me and elsewhere.
## Introduction
Common Vulnerabilities and Exposures (CVEs) are
Sentinelone
Prioritizing CVEs in the Cloud
blogs_sentinelone·2025-05-15
Prioritizing CVEs in the Cloud
## Foreword & Guest Bio
As part of this ongoing series, SentinelOne is excited to present a series of guest blogs from cloud security experts covering their views on cloud security best practices. Following on from blogs from Teri Radichel who focused on what AWS security gotchas to avoid and how to address the risk of faulty logic. We now have Rami McCarthy providing his view on cloud CVEs, and approach to vulnerability prioritization.
Rami is a self-proclaimed “security wonk”. Most recently, he helped build the Infrastructure Security program at Figma. Before that, he worked as a security consultant and helped scale security for a health-tech unicorn. He writes extensively about security over at ramimac.me and elsewhere.
## Introduction
Common Vulnerabilities and Exposures (CVEs) are
Wiz
IOC Security: The Role Of Indicators Of Compromise In Threat Detection | Wiz
blogs_wiz·2025-04-09
IOC Security: The Role Of Indicators Of Compromise In Threat Detection | Wiz
Indicators of compromise (IOCs) signal a potential security breach, acting as digital evidence of suspicious activity within a system or a network. By providing the context that computer security incident response teams (CSIRTs) need, IOCs help businesses neutralize attacks swiftly. This digital forensic data can also come in handy during post-event analysis to pinpoint the root cause of the breach and help teams strategize precautionary measures to prevent similar attacks in the future.
Remember: Threat actors are always improving their techniques—honing the use of automation, diverse attack vectors, artificial intelligence, and sophisticated invasion techniques—to infiltrate software systems undetected and achieve their malicious goals. IBM’s Cost of a Data Breach report from 2024 says
Wiz
IOC Security: The Role Of Indicators Of Compromise In Threat Detection | Wiz
blogs_wiz·2025-04-09
IOC Security: The Role Of Indicators Of Compromise In Threat Detection | Wiz
Indicators of compromise (IOCs) signal a potential security breach, acting as digital evidence of suspicious activity within a system or a network. By providing the context that computer security incident response teams ( CSIRTs ) need, IOCs help businesses neutralize attacks swiftly. This digital forensic data can also come in handy during post-event analysis to pinpoint the root cause of the breach and help teams strategize precautionary measures to prevent similar attacks in the future.
Remember: Threat actors are always improving their techniques—honing the use of automation, diverse attack vectors, artificial intelligence, and sophisticated invasion techniques—to infiltrate software systems undetected and achieve their malicious goals. IBM’s Cost of a Data Breach report from 2024 say
Dfir Report
Confluence Exploit Leads to LockBit Ransomware
blogs_dfir_report·2025-02-24·CVSS 9.8
[CRITICAL] Confluence Exploit Leads to LockBit Ransomware
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion Read More
- dragonforce Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs Read More
Services Overview
Threat Hunting
-
Integration
CTI Program Advisory
Incident Response Playbook
About us
Contact Us
Collaboration
Careers
Analysts
Access DFIR Labs
Get in Touch
Public Reports
Products Overview
Threat intel Overview
Threat Feed
Private DFIR Reports
All Intel
Active Defense
DFIR Labs
Case Artifacts
Detection Pack
AI Training Ground
Service Overview
Threat Hunting
Integration
CTI Program Advisory
Incident Response Playbook
Company Overview
About us
Contact Us
Careers
Analyst
SQL Brute Force Leads to BlueSky Ransomware
From OneNote to RansomNote: An Ice Col
Trendmicro
Attacker Abuses Victim Resources to Reap Rewards from Titan Network
blogs_trendmicro·2024-10-30·CVSS 9.8
CVE-2023-22527 [CRITICAL] Attacker Abuses Victim Resources to Reap Rewards from Titan Network
Cyber Threats
## Attacker Abuses Victim Resources to Reap Rewards from Titan Network
In this blog entry, we discuss how an attacker took advantage of the Atlassian Confluence vulnerability CVE-2023-22527 to connect servers to the Titan Network for cryptomining purposes.
By: Ranga Duraisamy, Sunil Bharti Oct 30, 2024 Read time: ( words)
Save to Folio
## Summary
Trend Micro researchers observed an attacker exploiting the Atlassian Confluence vulnerability CVE-2023-22527 to achieve remote code execution for cryptomining via the Titan Network.
The malicious actor used public IP lookup services and various system commands to gather details about the compromised machine.
The attack involved downloading and executing multiple shell scripts to install Titan binaries and connect to the Tita
Trendmicro
Attacker Abuses Victim Resources to Reap Rewards from Titan Network
blogs_trendmicro·2024-10-30·CVSS 9.8
CVE-2023-22527 [CRITICAL] Attacker Abuses Victim Resources to Reap Rewards from Titan Network
Cyber Threats
## Attacker Abuses Victim Resources to Reap Rewards from Titan Network
In this blog entry, we discuss how an attacker took advantage of the Atlassian Confluence vulnerability CVE-2023-22527 to connect servers to the Titan Network for cryptomining purposes.
By: Ranga Duraisamy, Sunil Bharti 2024/10/30 Read time: ( words)
Save to Folio
## Summary
Trend Micro researchers observed an attacker exploiting the Atlassian Confluence vulnerability CVE-2023-22527 to achieve remote code execution for cryptomining via the Titan Network.
The malicious actor used public IP lookup services and various system commands to gather details about the compromised machine.
The attack involved downloading and executing multiple shell scripts to install Titan binaries and connect to the Titan
Trendmicro
Attacker Abuses Victim Resources to Reap Rewards from Titan Network
blogs_trendmicro·2024-10-30·CVSS 9.8
CVE-2023-22527 [CRITICAL] Attacker Abuses Victim Resources to Reap Rewards from Titan Network
Ciberamenazas
## Attacker Abuses Victim Resources to Reap Rewards from Titan Network
In this blog entry, we discuss how an attacker took advantage of the Atlassian Confluence vulnerability CVE-2023-22527 to connect servers to the Titan Network for cryptomining purposes.
By: Ranga Duraisamy, Sunil Bharti Oct 30, 2024 Read time: ( words)
Save to Folio
## Summary
Trend Micro researchers observed an attacker exploiting the Atlassian Confluence vulnerability CVE-2023-22527 to achieve remote code execution for cryptomining via the Titan Network.
The malicious actor used public IP lookup services and various system commands to gather details about the compromised machine.
The attack involved downloading and executing multiple shell scripts to install Titan binaries and connect to the Tita
Trendmicro
Attacker Abuses Victim Resources to Reap Rewards from Titan Network
blogs_trendmicro·2024-10-30·CVSS 9.8
CVE-2023-22527 [CRITICAL] Attacker Abuses Victim Resources to Reap Rewards from Titan Network
Cyberbedrohungen
## Attacker Abuses Victim Resources to Reap Rewards from Titan Network
In this blog entry, we discuss how an attacker took advantage of the Atlassian Confluence vulnerability CVE-2023-22527 to connect servers to the Titan Network for cryptomining purposes.
By: Ranga Duraisamy, Sunil Bharti Oct 30, 2024 Read time: ( words)
Save to Folio
## Summary
Trend Micro researchers observed an attacker exploiting the Atlassian Confluence vulnerability CVE-2023-22527 to achieve remote code execution for cryptomining via the Titan Network.
The malicious actor used public IP lookup services and various system commands to gather details about the compromised machine.
The attack involved downloading and executing multiple shell scripts to install Titan binaries and connect to the T
Trendmicro
Attacker Abuses Victim Resources to Reap Rewards from Titan Network
blogs_trendmicro·2024-10-30·CVSS 9.8
CVE-2023-22527 [CRITICAL] Attacker Abuses Victim Resources to Reap Rewards from Titan Network
Cyber Threats
# Attacker Abuses Victim Resources to Reap Rewards from Titan Network
In this blog entry, we discuss how an attacker took advantage of the Atlassian Confluence vulnerability CVE-2023-22527 to connect servers to the Titan Network for cryptomining purposes.
By: Ranga Duraisamy, Sunil Bharti
2024/10/30
Read time: ( words)
Save to Folio
#### Summary
- Trend Micro researchers observed an attacker exploiting the Atlassian Confluence vulnerability CVE-2023-22527 to achieve remote code execution for cryptomining via the Titan Network.
- The malicious actor used public IP lookup services and various system commands to gather details about the compromised machine.
- The attack involved downloading and executing multiple shell scripts to install Titan binaries and connect to the
Wiz
Crying Out Cloud - October 2024 Newsletter | Wiz
blogs_wiz·2024-10-01·CVSS 9.0
CVE-2024-0132 [CRITICAL] Crying Out Cloud - October 2024 Newsletter | Wiz
Welcome back! In this edition, we bring you the latest in cloud security – noteworthy incidents, exclusive data, and crucial vulnerabilities. Let's dive in.
Here are our top picks!
## 🔍 Highlights
Critical Vulnerability in NVIDIA Container Toolkit
Wiz Research uncovered a critical vulnerability, CVE-2024-0132, in the widely used NVIDIA Container Toolkit. The vulnerability allows attackers with control over a container image to escape the container and gain full access to the underlying host. It is strongly recommended to update the affected package to the latest version 1.16.2, while focusing on container hosts that might run untrusted container images.
According to Wiz data, 33% of cloud environments are impacted by CVE-2024-0132.
Learn more in our blog .
## 🐞 High Profile Vulnerab
Trendmicro
Silent Intrusions: Godzilla Fileless Backdoors Targeting Atlassian Confluence
blogs_trendmicro·2024-08-30·CVSS 9.8
CVE-2023-22527 [CRITICAL] Silent Intrusions: Godzilla Fileless Backdoors Targeting Atlassian Confluence
Malware
# Silent Intrusions: Godzilla Fileless Backdoors Targeting Atlassian Confluence
Trend Micro discovered that old Atlassian Confluence versions that were affected by CVE-2023-22527 are being exploited using a new in-memory fileless backdoor.
By: Abdelrahman Esmail, Sunil Bharti
2024/08/30
Read time: ( words)
Save to Folio
#### Summary
- Trend Micro researchers identified a new attack vector that exploits the CVE-2023-22527 through the deployment of an in-memory fileless backdoor known as the Godzilla webshell. CVE-2023-22527 is a vulnerability affecting older versions of the Atlassian Confluence Data Center and Server that allows attackers to perform remote code execution.
- In such an attack, a loader is introduced into a compromised Atlassian server, subsequently activating
Trendmicro
Silent Intrusions: Godzilla Fileless Backdoors Targeting Atlassian Confluence
blogs_trendmicro·2024-08-30·CVSS 9.8
CVE-2023-22527 [CRITICAL] Silent Intrusions: Godzilla Fileless Backdoors Targeting Atlassian Confluence
Malware
## Silent Intrusions: Godzilla Fileless Backdoors Targeting Atlassian Confluence
Trend Micro discovered that old Atlassian Confluence versions that were affected by CVE-2023-22527 are being exploited using a new in-memory fileless backdoor.
By: Abdelrahman Esmail, Sunil Bharti 2024/08/30 Read time: ( words)
Save to Folio
## Summary
Trend Micro researchers identified a new attack vector that exploits the CVE-2023-22527 through the deployment of an in-memory fileless backdoor known as the Godzilla webshell. CVE-2023-22527 is a vulnerability affecting older versions of the Atlassian Confluence Data Center and Server that allows attackers to perform remote code execution.
In such an attack, a loader is introduced into a compromised Atlassian server, subsequently activating the G
Trendmicro
Silent Intrusions: Godzilla Fileless Backdoors Targeting Atlassian Confluence
blogs_trendmicro·2024-08-30·CVSS 9.8
CVE-2023-22527 [CRITICAL] Silent Intrusions: Godzilla Fileless Backdoors Targeting Atlassian Confluence
Malware
## Silent Intrusions: Godzilla Fileless Backdoors Targeting Atlassian Confluence
Trend Micro discovered that old Atlassian Confluence versions that were affected by CVE-2023-22527 are being exploited using a new in-memory fileless backdoor.
By: Abdelrahman Esmail, Sunil Bharti Aug 30, 2024 Read time: ( words)
Save to Folio
## Summary
Trend Micro researchers identified a new attack vector that exploits the CVE-2023-22527 through the deployment of an in-memory fileless backdoor known as the Godzilla webshell. CVE-2023-22527 is a vulnerability affecting older versions of the Atlassian Confluence Data Center and Server that allows attackers to perform remote code execution.
In such an attack, a loader is introduced into a compromised Atlassian server, subsequently activating the
Trendmicro
Cryptojacking via CVE-2023-22527: Dissecting a Full-Scale Cryptomining Ecosystem
blogs_trendmicro·2024-08-28·CVSS 9.8
CVE-2023-22527 [CRITICAL] Cryptojacking via CVE-2023-22527: Dissecting a Full-Scale Cryptomining Ecosystem
Ausnutzung von Schwachstellen
## Cryptojacking via CVE-2023-22527: Dissecting a Full-Scale Cryptomining Ecosystem
A technical analysis on how CVE-2023-22527 can be exploited by malicious actors for cryptojacking attacks that can spread across the victim’s system.
By: Abdelrahman Esmail Aug 28, 2024 Read time: ( words)
Save to Folio
Confluence Data Center and Server
8.0.x 8.1.x 8.2.x 8.3.x 8.4.x 8.5.0-8.5.3
Table 1. Affected Confluence Data Center and Confluence Server versions
We observed this vulnerability being weaponized for cryptomining activities. In addition, we noticed a high number of exploitations attempts since from mid-June to the end of July, 2024.
We observed three main threat actors exploiting CVE-2023-22527 via malicious scripts. The first threat actor using the XMR
Trendmicro
Cryptojacking via CVE-2023-22527: Dissecting a Full-Scale Cryptomining Ecosystem
blogs_trendmicro·2024-08-28·CVSS 9.8
CVE-2023-22527 [CRITICAL] Cryptojacking via CVE-2023-22527: Dissecting a Full-Scale Cryptomining Ecosystem
Exploits & Vulnerabilities
## Cryptojacking via CVE-2023-22527: Dissecting a Full-Scale Cryptomining Ecosystem
A technical analysis on how CVE-2023-22527 can be exploited by malicious actors for cryptojacking attacks that can spread across the victim’s system.
By: Abdelrahman Esmail 2024/08/28 Read time: ( words)
Save to Folio
Confluence Data Center and Server
8.0.x 8.1.x 8.2.x 8.3.x 8.4.x 8.5.0-8.5.3
Table 1. Affected Confluence Data Center and Confluence Server versions
We observed this vulnerability being weaponized for cryptomining activities. In addition, we noticed a high number of exploitations attempts since from mid-June to the end of July, 2024.
We observed three main threat actors exploiting CVE-2023-22527 via malicious scripts. The first threat actor using the XMRig mi
Trendmicro
Cryptojacking via CVE-2023-22527: Dissecting a Full-Scale Cryptomining Ecosystem
blogs_trendmicro·2024-08-28·CVSS 9.8
CVE-2023-22527 [CRITICAL] Cryptojacking via CVE-2023-22527: Dissecting a Full-Scale Cryptomining Ecosystem
Exploits y vulnerabilidades
## Cryptojacking via CVE-2023-22527: Dissecting a Full-Scale Cryptomining Ecosystem
A technical analysis on how CVE-2023-22527 can be exploited by malicious actors for cryptojacking attacks that can spread across the victim’s system.
By: Abdelrahman Esmail Aug 28, 2024 Read time: ( words)
Save to Folio
Confluence Data Center and Server
8.0.x 8.1.x 8.2.x 8.3.x 8.4.x 8.5.0-8.5.3
Table 1. Affected Confluence Data Center and Confluence Server versions
We observed this vulnerability being weaponized for cryptomining activities. In addition, we noticed a high number of exploitations attempts since from mid-June to the end of July, 2024.
We observed three main threat actors exploiting CVE-2023-22527 via malicious scripts. The first threat actor using the XMRig
Trendmicro
Cryptojacking via CVE-2023-22527: Dissecting a Full-Scale Cryptomining Ecosystem
blogs_trendmicro·2024-08-28·CVSS 9.8
CVE-2023-22527 [CRITICAL] Cryptojacking via CVE-2023-22527: Dissecting a Full-Scale Cryptomining Ecosystem
Exploits & Vulnerabilities
## Cryptojacking via CVE-2023-22527: Dissecting a Full-Scale Cryptomining Ecosystem
A technical analysis on how CVE-2023-22527 can be exploited by malicious actors for cryptojacking attacks that can spread across the victim’s system.
By: Abdelrahman Esmail Aug 28, 2024 Read time: ( words)
Save to Folio
Confluence Data Center and Server
8.0.x 8.1.x 8.2.x 8.3.x 8.4.x 8.5.0-8.5.3
Table 1. Affected Confluence Data Center and Confluence Server versions
We observed this vulnerability being weaponized for cryptomining activities. In addition, we noticed a high number of exploitations attempts since from mid-June to the end of July, 2024.
We observed three main threat actors exploiting CVE-2023-22527 via malicious scripts. The first threat actor using the XMRig
Trendmicro
Cryptojacking via CVE-2023-22527: Dissecting a Full-Scale Cryptomining Ecosystem
blogs_trendmicro·2024-08-28·CVSS 9.8
CVE-2023-22527 [CRITICAL] Cryptojacking via CVE-2023-22527: Dissecting a Full-Scale Cryptomining Ecosystem
Exploits & Vulnerabilities
# Cryptojacking via CVE-2023-22527: Dissecting a Full-Scale Cryptomining Ecosystem
A technical analysis on how CVE-2023-22527 can be exploited by malicious actors for cryptojacking attacks that can spread across the victim’s system.
By: Abdelrahman Esmail
2024/08/28
Read time: ( words)
Save to Folio
# Summary
- The critical vulnerability CVE-2023-22527 is actively being exploited for cryptojacking activities, turning affected environments into cryptomining networks.
- The attacks involve threat actors that employ methods such as the deployment of shell scripts and XMRig miners, targeting of SSH endpoints, killing competing cryptomining processes, and maintaining persistence via cron jobs.
- Organizations are advised to update their Confluence instances to
Qualys
Cybersecurity Threat Landscape 2024 Midyear Review
blogs_qualys·2024-08-06
Cybersecurity Threat Landscape 2024 Midyear Review
## Table of Contents
Key Takeaways from the Threat Landscape Report 2024
Vulnerability and Threat Analysis in the Cybersecurity Landscape 2024
Cyber Threat Landscape 2024 A Detailed Review
Key Statistics and Their Impact on the 2024 Cybersecurity Landscape
Mid-2024s Most Exploited Vulnerabilities in the Cybersecurity Landscape
Conclusion
As we navigate the complexities of 2024, it’s crucial to pause and reflect on the evolving threat landscape that surrounds us. This moment offers a unique opportunity to scrutinize our triumphs and missteps, understand the events that have decisively shaped our environment, and consider those that have subtly influenced it. By extracting key lessons from our recent experiences, we can fortify our strategies and prepare more effectively for the emerg
Qualys
Qualys Midyear 2024 Threat Landscape Analysis and Insights | Qualys
blogs_qualys·2024-08-06
Qualys Midyear 2024 Threat Landscape Analysis and Insights | Qualys
#### Table of Contents
- Key Takeaways from the Threat Landscape Report 2024
- Vulnerability and Threat Analysis in the Cybersecurity Landscape 2024
- Cyber Threat Landscape 2024 A Detailed Review
- Key Statistics and Their Impact on the 2024 Cybersecurity Landscape
- Mid-2024s Most Exploited Vulnerabilities in the Cybersecurity Landscape
- Conclusion
As we navigate the complexities of 2024, it’s crucial to pause and reflect on the evolving threat landscape that surrounds us. This moment offers a unique opportunity to scrutinize our triumphs and missteps, understand the events that have decisively shaped our environment, and consider those that have subtly influenced it. By extracting key lessons from our recent experiences, we can fortify our strategies and prepare more effectively for
Wiz
Crying Out Cloud - March 2024 Newsletter | Wiz
blogs_wiz·2024-03-01·CVSS 8.6
CVE-2024-21626 [HIGH] Crying Out Cloud - March 2024 Newsletter | Wiz
Welcome back! In this edition, we bring you the latest in cloud security – crucial vulnerabilities, exclusive data, and noteworthy incidents. Stay informed and stay secure. Let's delve in.
Here are our cloud security highlights!
## 🐞 High Profile Vulnerabilities
Leaky Vessels: Docker and runc Container Escape Vulnerabilities
Several vulnerabilities have been revealed in the runC command line tool (CVE-2024-21626, CVE-2024-23651, CVE-2024-23652, and CVE-2024-23653). These flaws pose a risk of container escape, exploiting these vulnerabilities could grant unauthorized access to the host operating system, potentially compromising sensitive data and facilitating further attacks, particularly with superuser privileges.
According to Wiz data, 18% percent of cloud environments have resources
Trendmicro
Unveiling Atlassian Confluence Vulnerability CVE-2023-22527: Understanding and Mitigating Remote Code Execution Risks
blogs_trendmicro·2024-02-07·CVSS 9.8
CVE-2023-22527 [CRITICAL] Unveiling Atlassian Confluence Vulnerability CVE-2023-22527: Understanding and Mitigating Remote Code Execution Risks
Exploits & Vulnerabilities
## Unveiling Atlassian Confluence Vulnerability CVE-2023-22527: Understanding and Mitigating Remote Code Execution Risks
In this blog entry, we discuss CVE-2023-22527, a vulnerability in Atlassian Confluence that has a CVSS score of 10 and could allow threat actors to perform remote code execution.
By: Jagir Shastri, Bhumi Patel, Neharika Razdan Feb 07, 2024 Read time: ( words)
Save to Folio
Object-Graph Navigation Language (OGNL) is an open-source component of many web applications, known for its role in the infamous Equifax attack within the Apache Struts framework. However, a new critical flaw in Atlassian Confluence, CVE-2023-22527, has made OGNL susceptible to exploitation for malicious activity. This vulnerability has a Common Vulnerability Scoring Sys
Trendmicro
Unveiling Atlassian Confluence Vulnerability CVE-2023-22527: Understanding and Mitigating Remote Code Execution Risks
blogs_trendmicro·2024-02-07·CVSS 9.8
CVE-2023-22527 [CRITICAL] Unveiling Atlassian Confluence Vulnerability CVE-2023-22527: Understanding and Mitigating Remote Code Execution Risks
Exploits & Vulnerabilities
# Unveiling Atlassian Confluence Vulnerability CVE-2023-22527: Understanding and Mitigating Remote Code Execution Risks
In this blog entry, we discuss CVE-2023-22527, a vulnerability in Atlassian Confluence that has a CVSS score of 10 and could allow threat actors to perform remote code execution.
By: Jagir Shastri, Bhumi Patel, Neharika Razdan
2024/02/07
Read time: ( words)
Save to Folio
Object-Graph Navigation Language (OGNL) is an open-source component of many web applications, known for its role in the infamous Equifax attack within the Apache Struts framework. However, a new critical flaw in Atlassian Confluence, CVE-2023-22527, has made OGNL susceptible to exploitation for malicious activity. This vulnerability has a Common Vulnerability Scoring Syste
Trendmicro
Unveiling Atlassian Confluence Vulnerability CVE-2023-22527: Understanding and Mitigating Remote Code Execution Risks
blogs_trendmicro·2024-02-07·CVSS 9.8
CVE-2023-22527 [CRITICAL] Unveiling Atlassian Confluence Vulnerability CVE-2023-22527: Understanding and Mitigating Remote Code Execution Risks
Exploits & Vulnerabilities
## Unveiling Atlassian Confluence Vulnerability CVE-2023-22527: Understanding and Mitigating Remote Code Execution Risks
In this blog entry, we discuss CVE-2023-22527, a vulnerability in Atlassian Confluence that has a CVSS score of 10 and could allow threat actors to perform remote code execution.
By: Jagir Shastri, Bhumi Patel, Neharika Razdan 2024/02/07 Read time: ( words)
Save to Folio
Object-Graph Navigation Language (OGNL) is an open-source component of many web applications, known for its role in the infamous Equifax attack within the Apache Struts framework. However, a new critical flaw in Atlassian Confluence, CVE-2023-22527, has made OGNL susceptible to exploitation for malicious activity. This vulnerability has a Common Vulnerability Scoring Syste
Trendmicro
Unveiling Atlassian Confluence Vulnerability CVE-2023-22527: Understanding and Mitigating Remote Code Execution Risks
blogs_trendmicro·2024-02-07·CVSS 9.8
CVE-2023-22527 [CRITICAL] Unveiling Atlassian Confluence Vulnerability CVE-2023-22527: Understanding and Mitigating Remote Code Execution Risks
Exploits & Vulnerabilities
## Unveiling Atlassian Confluence Vulnerability CVE-2023-22527: Understanding and Mitigating Remote Code Execution Risks
In this blog entry, we discuss CVE-2023-22527, a vulnerability in Atlassian Confluence that has a CVSS score of 10 and could allow threat actors to perform remote code execution.
By: Jagir Shastri Feb 07, 2024 Read time: ( words)
Save to Folio
Object-Graph Navigation Language (OGNL) is an open-source component of many web applications, known for its role in the infamous Equifax attack within the Apache Struts framework. However, a new critical flaw in Atlassian Confluence, CVE-2023-22527, has made OGNL susceptible to exploitation for malicious activity. This vulnerability has a Common Vulnerability Scoring System (CVSS) score of 10 and ena
Trendmicro
Unveiling Atlassian Confluence Vulnerability CVE-2023-22527: Understanding and Mitigating Remote Code Execution Risks
blogs_trendmicro·2024-02-07·CVSS 9.8
CVE-2023-22527 [CRITICAL] Unveiling Atlassian Confluence Vulnerability CVE-2023-22527: Understanding and Mitigating Remote Code Execution Risks
Exploits y vulnerabilidades
## Unveiling Atlassian Confluence Vulnerability CVE-2023-22527: Understanding and Mitigating Remote Code Execution Risks
In this blog entry, we discuss CVE-2023-22527, a vulnerability in Atlassian Confluence that has a CVSS score of 10 and could allow threat actors to perform remote code execution.
By: Jagir Shastri Feb 07, 2024 Read time: ( words)
Save to Folio
Object-Graph Navigation Language (OGNL) is an open-source component of many web applications, known for its role in the infamous Equifax attack within the Apache Struts framework. However, a new critical flaw in Atlassian Confluence, CVE-2023-22527, has made OGNL susceptible to exploitation for malicious activity. This vulnerability has a Common Vulnerability Scoring System (CVSS) score of 10 and en
Trendmicro
Unveiling Atlassian Confluence Vulnerability CVE-2023-22527: Understanding and Mitigating Remote Code Execution Risks
blogs_trendmicro·2024-02-07·CVSS 9.8
CVE-2023-22527 [CRITICAL] Unveiling Atlassian Confluence Vulnerability CVE-2023-22527: Understanding and Mitigating Remote Code Execution Risks
Ausnutzung von Schwachstellen
## Unveiling Atlassian Confluence Vulnerability CVE-2023-22527: Understanding and Mitigating Remote Code Execution Risks
In this blog entry, we discuss CVE-2023-22527, a vulnerability in Atlassian Confluence that has a CVSS score of 10 and could allow threat actors to perform remote code execution.
By: Jagir Shastri Feb 07, 2024 Read time: ( words)
Save to Folio
Object-Graph Navigation Language (OGNL) is an open-source component of many web applications, known for its role in the infamous Equifax attack within the Apache Struts framework. However, a new critical flaw in Atlassian Confluence, CVE-2023-22527, has made OGNL susceptible to exploitation for malicious activity. This vulnerability has a Common Vulnerability Scoring System (CVSS) score of 10 and
Wiz
Crying Out Cloud - February Newsletter | Wiz
blogs_wiz·2024-02-01·CVSS 9.8
CVE-2023-33246 [CRITICAL] Crying Out Cloud - February Newsletter | Wiz
This month we’ve seen a lot of action, with both vulnerabilities and security incidents that have left users affected. We bring you the latest cloud security highlights, to help you stay informed and stay secure. Let's dive in.
Here are our top picks!
## 🐞 High Profile Vulnerabilities
Apache RocketMQ RCE vulnerability exploited in-the-wild
In August 2023 researchers identified attackers exploiting CVE-2023-33246, a critical vulnerability in Apache RocketMQ, to install the DreamBus bot, a malware strain last reported about publicly in 2021. On January 5, 2024 Apache stated that the patch for CVE-2023-33246 was in fact insufficient, and an additional CVE was assigned to the bypass - CVE-2023-37582. The latter vulnerability is also being exploited in the wild, so it is recommended to patc
Tenable
CVE-2023-22527: Atlassian Confluence Data Center and Server Template Injection Exploited in the Wild
blogs_tenable·2024-01-23·CVSS 9.8
[CRITICAL] CVE-2023-22527: Atlassian Confluence Data Center and Server Template Injection Exploited in the Wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
22nd January – Threat Intelligence Report
blogs_checkpoint·2024-01-22
CVE-2023-34063 22nd January – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 22nd January – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 22nd January, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Microsoft disclosed that they detected an attack against their systems by Russian state-sponsored actor known as Midnight Blizzard (aka Nobelium). The threat actor used a password spray attack to compromise a legacy non-production test tenant account and then accessed very small percentage of Microsoft corporate email acc
Bleepingcomputer
Hackers start exploiting critical Atlassian Confluence RCE flaw
blogs_bleepingcomputer·2024-01-22·CVSS 9.8
CVE-2023-22527 [CRITICAL] Hackers start exploiting critical Atlassian Confluence RCE flaw
## Hackers start exploiting critical Atlassian Confluence RCE flaw
## Bill Toulas
Security researchers are observing exploitation attempts for the CVE-2023-22527 remote code execution flaw vulnerability that affects outdated versions of Atlassian Confluence servers.
Atlassian disclosed the security issue last week and noted that it impacts only Confluence versions released before December 5, 2023, along with some out-of-support releases.
The flaw has a critical severity score and is described as a template injection weakness that allows unauthenticated remote attackers to execute code on vulnerable Confluence Data Center and Confluence Server endpoints, versions versions 8.0.x, 8.1.x, 8.2.x, 8.3.x, 8.4.x, and 8.5.0 through 8.5.3.
A fix is available for Confluence Data Center and Serve
Bleepingcomputer
Atlassian warns of critical RCE flaw in older Confluence versions
blogs_bleepingcomputer·2024-01-16·CVSS 9.8
CVE-2023-22527 [CRITICAL] Atlassian warns of critical RCE flaw in older Confluence versions
## Atlassian warns of critical RCE flaw in older Confluence versions
## Bill Toulas
Atlassian Confluence Data Center and Confluence Server are vulnerable to a critical remote code execution (RCE) vulnerability that impacts versions released before December 5, 2023, including out-of-support releases.
The flaw is tracked as CVE-2023-22527, rated critical (CVSS v3: 10.0), and is a template injection vulnerability allowing unauthenticated attackers to perform remote code execution on impacted Confluence endpoints.
"Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular updates," reads Atlassian's security bulletin .
"However, Atlassian recommends that customers take care to install the latest
Greynoiseio
Storm Watch
blogs_greynoiseio
Storm Watch
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
NoiseLetter March 2024
blogs_greynoiseio
NoiseLetter March 2024
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
Where are they now? Starring: Atlassian's Confluence CVE-2023-22527
blogs_greynoiseio·CVSS 9.8
[CRITICAL] Where are they now? Starring: Atlassian's Confluence CVE-2023-22527
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
arXiv
Efficacy of EPSS in High Severity CVEs found in KEV
arxiv_fulltext·2024-11-04
Efficacy of EPSS in High Severity CVEs found in KEV
empty
empty
24pt
10pt plus 1.0pt minus 2.0pt
## Abstract
The Exploit Prediction Scoring System (EPSS) is designed to assess the probability of a vulnerability being exploited in the next 30 days relative to other vulnerabilities. The latest version, based on a research paper published in arXiv , assists defenders in deciding which vulnerabilities to prioritize for remediation. This study evaluates EPSS's ability to predict exploitation before vulnerabilities are actively compromised, focusing on high severity CVEs that are known to have been exploited and included in the CISA KEV catalog. By analyzing EPSS score history, the availability and simplicity of exploits, the system's purpose, its value as a target for Threat Actors (TAs), this paper examines EPSS's potential and identifies ar
http://packetstormsecurity.com/files/176789/Atlassian-Confluence-SSTI-Injection.htmlhttps://confluence.atlassian.com/pages/viewpage.action?pageId=1333335615https://jira.atlassian.com/browse/CONFSERVER-93833http://packetstormsecurity.com/files/176789/Atlassian-Confluence-SSTI-Injection.htmlhttps://confluence.atlassian.com/pages/viewpage.action?pageId=1333335615https://jira.atlassian.com/browse/CONFSERVER-93833https://www.vicarius.io/vsociety/posts/pwning-confluence-via-ognl-injection-for-fun-and-learning-cve-2023-22527https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-22527
2024-01-16
Published
2024-01-24
Added to CISA KEV
Exploited in the wild