QID 150780

Date Published: 2024-01-25

QID 150780: Atlassian Confluence Data Center and Server Remote Code Execution (RCE) Vulnerability (CVE-2023-22527) (Exploitation Check)

Confluence is a team collaboration software written in Java and mainly used in corporate environments, it is developed and marketed by Atlassian.

A Template Injection Vulnerability exists on out-of-date versions of Confluence Data Center and Server which allows an unauthenticated attacker to trigger Remote Code Execution (RCE).

Affected versions:
Confluence Data Center and Server 8.0.x
Confluence Data Center and Server 8.1.x
Confluence Data Center and Server 8.2.x
Confluence Data Center and Server 8.3.x
Confluence Data Center and Server 8.4.x
Confluence Data Center and Server 8.5.0 to 8.5.3

QID Detection Logic (Unauthenticated) :
This QID sends an HTTP POST request to "template/aui/text-inline.vm" endpoint with crafted payload and based on the response determines if the target Confluence instance is vulnerable.

Successful exploitation of this vulnerability could allow an unauthenticated attacker to execute arbitrary code on the target Confluence instance.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to upgrade Confluence Data Center and Server to version 8.5.4 (LTS) or later and version 8.6.0, 8.6.1 or later for Data Center Only. For more information pertaining to remediating this vulnerability please refer Atlassian Security Advisory.

    CVEs related to QID 150780

    Software Advisories
    Advisory ID Software Component Link
    Atlassian Security Advisory URL Logo confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html