RCE Vulnerability in Confluence Data Center & Server by Atlassian
CVE-2023-22505
8HIGH
Key Information:
- Vendor
- Atlassian
- Vendor
- CVE Published:
- 18 July 2023
Summary
A Remote Code Execution vulnerability has been identified in versions of Confluence Data Center & Server starting from 8.0.0. This flaw enables an authenticated attacker to run arbitrary code without user interaction, potentially compromising confidentiality, integrity, and availability of the system. Atlassian strongly advises users to upgrade to the latest version to mitigate risks associated with this vulnerability. If immediate upgrading is not feasible, users should update to fixed versions 8.3.2 or 8.4.0 as detailed in the official release notes.
Affected Version(s)
Confluence Data Center >= 8.0.0 < 8.0.0
Confluence Server >= 8.0.0 < 8.0.0
Confluence Data Center < 8.0.0 < 8.0.0
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
a private user