QID 150779

Date Published: 2024-01-23

QID 150779: Atlassian Confluence Data Center and Server Remote Code Execution (RCE) Vulnerability (CVE-2023-22527)

Confluence is a team collaboration software written in Java and mainly used in corporate environments, it is developed and marketed by Atlassian.

A Template Injection Vulnerability exists on out-of-date versions of Confluence Data Center and Server which allows an unauthenticated attacker to achieve RCE on an affected version.

Affected versions:
Confluence Data Center and Server 8.0.x
Confluence Data Center and Server 8.1.x
Confluence Data Center and Server 8.2.x
Confluence Data Center and Server 8.3.x
Confluence Data Center and Server 8.4.x
Confluence Data Center and Server 8.5.0 to 8.5.3

QID Detection Logic (Unauthenticated) :
This QID sends HTTP GET request and checks for vulnerable version of Confluence running on the host.

Successful exploitation of this vulnerability could allow an unauthenticated attacker to achieve Remote Code Execution (RCE) on the target Confluence instance.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to upgrade Confluence Data Center and Server to version 8.5.4 (LTS) or later and version 8.6.0, 8.6.1 or later for Data Center Only. For more information pertaining to remediating this vulnerability please refer Atlassian Security Advisory.

    CVEs related to QID 150779

    Software Advisories
    Advisory ID Software Component Link
    Atlassian Security Advisory URL Logo confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html