QID 150780
Date Published: 2024-01-25
QID 150780: Atlassian Confluence Data Center and Server Remote Code Execution (RCE) Vulnerability (CVE-2023-22527) (Exploitation Check)
Confluence is a team collaboration software written in Java and mainly used in corporate environments, it is developed and marketed by Atlassian.
A Template Injection Vulnerability exists on out-of-date versions of Confluence Data Center and Server which allows an unauthenticated attacker to trigger Remote Code Execution (RCE).
Affected versions:
Confluence Data Center and Server 8.0.x
Confluence Data Center and Server 8.1.x
Confluence Data Center and Server 8.2.x
Confluence Data Center and Server 8.3.x
Confluence Data Center and Server 8.4.x
Confluence Data Center and Server 8.5.0 to 8.5.3
QID Detection Logic (Unauthenticated) :
This QID sends an HTTP POST request to "template/aui/text-inline.vm" endpoint with crafted payload and based on the response determines if the target Confluence instance is vulnerable.
Successful exploitation of this vulnerability could allow an unauthenticated attacker to execute arbitrary code on the target Confluence instance.
CVEs related to QID 150780
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Atlassian Security Advisory |
|