cbcvebase.
CVE-2023-22527
published 2024-01-16

CVE-2023-22527: A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected…

PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2024-02-14
Exploited in the wild
EPSS
99.98%
100.0th percentile
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.

Affected

22 ranges
VendorProductVersion rangeFixed in
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center
atlassianconfluence_data_center>= 8.0.0 < 8.5.48.5.4
atlassianconfluence_server
atlassianconfluence_server
atlassianconfluence_server
atlassianconfluence_server
atlassianconfluence_server
atlassianconfluence_server
atlassianconfluence_server
atlassianconfluence_server
atlassianconfluence_server
atlassianconfluence_server>= 8.0.0 < 8.5.48.5.4

Detection & IOCsextracted from sources · hover to see the quote

path/confluence/template/aui/text-inline.vm
command#request.get(.KEY_velocity.struts2.context).internalGet(ognl).findValue(#parameters.poc[0],{})&[email protected]@getResponse().setHeader('Cmd-Ret',(new freemarker.template.utility.Execute()).exec({"id"}))
  • Monitor HTTP requests targeting the vulnerable endpoint /confluence/template/aui/text-inline.vm for OGNL/FreeMarker injection patterns in the 'label' parameter.
  • Detect exploit payloads containing the string '.KEY_velocity.struts2.context' or '.freemarker.TemplateModel' in HTTP request bodies to Confluence endpoints.
  • Detect cron job creation under names 'whoami', 'nginx', or 'apache' in /etc/init.d, /etc/cron.hourly, or /etc/cron.d as post-exploitation persistence indicators.
  • Apply Trend Micro DPI/DDI rule references for network-level detection of CVE-2023-22527 exploit traffic.
  • ·The vulnerable endpoint /confluence/template/aui/text-inline.vm has been removed in patched versions; its presence on a server confirms an unpatched instance.
  • ·There are no known workarounds for CVE-2023-22527; patching to 8.5.4+ (Server/DC) or 8.6.0+/8.7.1+ (DC only) is the only remediation.
  • ·The attacker's script actively kills known security/monitoring agents (Alibaba Cloud Shield, Tencent Cloud) and clears logs/bash history, reducing forensic visibility on compromised hosts.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.