⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.. Due date: 2024-02-14.

CVE-2023-22527

CWE-7432 documents12 sources
Severity
9.8CRITICAL
EPSS
94.4%
top 0.04%
CISA KEV
KEVRansomware
Added 2024-01-24
Due 2024-02-14
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJan 16
KEV addedJan 24
KEV dueFeb 14
Latest updateOct 30
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect thei

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

NVDatlassian/confluence_data_center8.0.08.5.4+1
CVEListV5atlassian/confluence_data_center9 versions+8
NVDatlassian/confluence_server8.0.08.5.4
CVEListV5atlassian/confluence_server9 versions+8

🔴Vulnerability Details

3
CVEList
CVE-2023-22527: A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affe2024-01-16
GHSA
GHSA-w64x-j9r3-q79q: Summary of Vulnerability A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker2024-01-16
VulnCheck
Atlassian Confluence Data Center and Server Template Injection Vulnerability2023

💥Exploits & PoCs

1
Nuclei
Atlassian Confluence - Remote Code Execution

🔍Detection Rules

2
Suricata
ET EXPLOIT Atlassian Confluence RCE Attempt Observed (CVE-2023-22527) M22024-01-29
Suricata
ET EXPLOIT Atlassian Confluence RCE Attempt Observed (CVE-2023-22527) M12024-01-23

📋Vendor Advisories

2
CISA
Atlassian Confluence Data Center and Server Template Injection Vulnerability2024-01-24
Atlassian
CVE-2023-22527 - RCE (Remote Code Execution) Vulnerability in Out-of-Date Versions of Confluence Data Center and Server

🕵️Threat Intelligence

21
Trendmicro
Attacker Abuses Victim Resources to Reap Rewards from Titan Network2024-10-30
Trendmicro
Attacker Abuses Victim Resources to Reap Rewards from Titan Network2024-10-30
Trendmicro
Attacker Abuses Victim Resources to Reap Rewards from Titan Network2024-10-30
Trendmicro
Attacker Abuses Victim Resources to Reap Rewards from Titan Network2024-10-30
Trendmicro
Attacker Abuses Victim Resources to Reap Rewards from Titan Network2024-10-30