Skip to main content

Atlassian Releases Security Updates for Zero Day Vulnerability in Confluence Data Center and Server

The security update addresses a broken access control vulnerability in Confluence Data Center and Server

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

The security update addresses a broken access control vulnerability in Confluence Data Center and Server


Threat details

Introduction

Atlassian has released a security update to address a zero day vulnerability in Confluence Data Center and Server. The critical vulnerability, known as CVE-2023-22515, has a CVSSv3 score of 10. The vulnerability can be exploited by an attacker to create unauthorised Confluence administrator accounts and access Confluence instances.

Atlassian has confirmed that Atlassian Cloud sites and Confluence sites which are accessed via an atlassian.net domain, are not vulnerable to this issue.

Exploitation of CVE-2023-22515

Atlassian have reported that CVE-2023-22515 is being actively exploited in the wild.


Remediation advice

Affected organisations are encouraged to review the following Atlassian security advisory and upgrade to a fixed version.



Last edited: 9 October 2023 1:25 pm