Atlassian Releases Security Updates for Zero Day Vulnerability in Confluence Data Center and Server
The security update addresses a broken access control vulnerability in Confluence Data Center and Server
Summary
The security update addresses a broken access control vulnerability in Confluence Data Center and Server
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Atlassian has released a security update to address a zero day vulnerability in Confluence Data Center and Server. The critical vulnerability, known as CVE-2023-22515, has a CVSSv3 score of 10. The vulnerability can be exploited by an attacker to create unauthorised Confluence administrator accounts and access Confluence instances.
Atlassian has confirmed that Atlassian Cloud sites and Confluence sites which are accessed via an atlassian.net domain, are not vulnerable to this issue.
Exploitation of CVE-2023-22515
Atlassian have reported that CVE-2023-22515 is being actively exploited in the wild.
Remediation advice
Affected organisations are encouraged to review the following Atlassian security advisory and upgrade to a fixed version.
Definitive source of threat updates
Last edited: 9 October 2023 1:25 pm