QID 378914

Date Published: 2023-10-04

QID 378914: Atlassian Confluence Server and Data Center Privilege Escalation Vulnerability (CONFSERVER-92475)

Confluence is team collaboration software written in Java.



Affected version:
Versions 8.0.0, 8.1.0, 8.2.0, 8.3.0, 8.4.0, 8.5.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.1.1, 8.1.3, 8.2.1, 8.1.4, 8.2.2, 8.2.3, 8.3.1, 8.3.2, 8.4.1, 8.4.2, and 8.5.1


QID Detection Logic(authenticated):
Operating System: (Windows) The QID checks for vulnerable versions of Confluence Server.BR> Note: The QID will only detect MSI installation on Windows.
Note: Currently, the QID is a potential detection because it does not check if mitigations are applied instead of the patch.

Operating System: (Unix)
The QID checks for vulnerable versions of Confluence Server and checks for mitigation advised by the vendor.
Note: Currently, the QID is a potential detection because it does not check if mitigations are applied instead of the patch.

Successful exploitation of this vulnerability could lead to a security breach or could affect confidentiality, integrity, and availability.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to refer to CONFSERVER-92475 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 378914

    Software Advisories
    Advisory ID Software Component Link
    Confluence Security Advisory URL Logo jira.atlassian.com/browse/CONFSERVER-92475