PT-2024-1074 · Atlassian · Confluence
Petrus Viet
+1
·
Published
2024-01-15
·
Updated
2025-09-22
·
CVE-2023-22527
CVSS v3.1
10
10
Critical
Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Atlassian Confluence versions 8.0.x through 8.5.3
Description
A template injection vulnerability in older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve remote code execution (RCE) on an affected instance. The vulnerability is being actively exploited by threat actors, with over 39,000 attempts to exploit it recorded in just three days. The exploitation of this vulnerability can lead to unauthorized code execution, allowing attackers to install malware, steal sensitive data, or disrupt operations.
Recommendations
To resolve the issue, update Confluence to version 8.5.4 or later. For versions prior to 8.5.4, apply the patch provided by Atlassian to fix the vulnerability. Additionally, consider implementing security measures such as restricting access to the vulnerable module, disabling the vulnerable function, and monitoring for suspicious activity.
Note: The provided information is based on the given input and does not include any external knowledge or information not present in the input.
Exploit
Fix
RCE
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2024-00325
CVE-2023-22527
Affected Products
Confluence
References · 441
- 🔥 https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/atlassian_confluence_rce_cve_2023_22527.rb⭐ 34302 🔗 14014 · Exploit
- 🔥 https://github.com/Boogipop/CVE-2023-22527-Godzilla-MEMSHELL⭐ 73 🔗 9 · Exploit
- 🔥 https://github.com/M0untainShley/CVE-2023-22527-MEMSHELL⭐ 37 🔗 1 · Exploit
- 🔥 https://github.com/Avento/CVE-2023-22527_Confluence_RCE⭐ 25 🔗 4 · Exploit
- 🔥 https://github.com/Manh130902/CVE-2023-22527-POC⭐ 20 🔗 3 · Exploit
- 🔥 https://github.com/VNCERT-CC/CVE-2023-22527-confluence⭐ 18 🔗 5 · Exploit
- 🔥 https://github.com/Vozec/CVE-2023-22527⭐ 13 🔗 1 · Exploit
- 🔥 https://github.com/sanjai-AK47/CVE-2023-22527⭐ 9 🔗 5 · Exploit
- 🔥 https://github.com/RevoltSecurities/CVE-2023-22527⭐ 9 🔗 5 · Exploit
- 🔥 https://github.com/Chocapikk/CVE-2023-22527⭐ 9 🔗 2 · Exploit
- 🔥 https://github.com/thanhlam-attt/CVE-2023-22527⭐ 5 🔗 1 · Exploit
- 🔥 https://github.com/adminlove520/CVE-2023-22527⭐ 5 · Exploit
- 🔥 https://github.com/yoryio/CVE-2023-22527⭐ 4 🔗 1 · Exploit
- 🔥 https://github.com/C1ph3rX13/CVE-2023-22527⭐ 4 🔗 1 · Exploit
- 🔥 https://github.com/vulncheck-oss/cve-2023-22527⭐ 3 🔗 2 · Exploit