PT-2024-1275 · Atlassian · Confluence

M1Sn0W

·

Published

2024-01-15

·

Updated

2024-01-22

·

CVE-2023-22526

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Confluence Data Center and Server versions 7.19.0 through 7.19.16 Confluence Data Center and Server versions 8.5.0 through 8.5.4 Confluence Data Center versions 8.7.0 through 8.7.1
Description The issue is related to insufficient input validation, allowing a remote attacker to execute arbitrary code. This has a high impact on confidentiality, integrity, and availability, and requires no user interaction. The vulnerability was discovered by m1sn0w and reported via the Bug Bounty program.
Recommendations For Confluence Data Center and Server version 7.19: Upgrade to a release 7.19.17, or any higher 7.19.x release For Confluence Data Center and Server version 8.5: Upgrade to a release 8.5.5 or any higher 8.5.x release For Confluence Data Center version 8.7: Upgrade to a release 8.7.2 or any higher release

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2024-00701
CVE-2023-22526

Affected Products

Confluence