QID 150738

Date Published: 2023-11-06

QID 150738: Atlassian Confluence Server and Data Center Improper Authorization Vulnerability (CVE-2023-22518)

Confluence is a team collaboration software written in Java and mainly used in corporate environments, it is developed and marketed by Atlassian.

Multiple versions of Atlassian Confluence are affected by an Improper Authorization Vulnerability.

Affected versions:
Confluence versions prior to 7.19.16
Confluence versions prior to 8.3.4
Confluence versions prior to 8.4.4
Confluence versions prior to 8.5.3
Confluence versions prior to 8.6.1

QID Detection Logic (Unauthenticated):
This QID sends HTTP GET request and checks for vulnerable version of Confluence running on the host.

Successful exploitation of this vulnerability could affect Integrity and Availability of the target Confluence instance.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as Critical - 9.4 severity.
  • Solution
    Atlassian has released a fix to address this issue. Customers are advised to upgrade to Confluence version 7.19.16, 8.3.4, 8.4.4, 8.5.3, 8.6.1 or later. For more information pertaining to remediating this vulnerability please refer Atlassian Security Advisory.

    CVEs related to QID 150738

    Software Advisories
    Advisory ID Software Component Link
    Atlassian Security Advisory URL Logo confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html