RCE Vulnerability in Confluence Data Center & Server by Atlassian
CVE-2023-22505

8HIGH

Key Information:

Vendor
Atlassian
Vendor
CVE Published:
18 July 2023

Summary

A Remote Code Execution vulnerability has been identified in versions of Confluence Data Center & Server starting from 8.0.0. This flaw enables an authenticated attacker to run arbitrary code without user interaction, potentially compromising confidentiality, integrity, and availability of the system. Atlassian strongly advises users to upgrade to the latest version to mitigate risks associated with this vulnerability. If immediate upgrading is not feasible, users should update to fixed versions 8.3.2 or 8.4.0 as detailed in the official release notes.

Affected Version(s)

Confluence Data Center >= 8.0.0 < 8.0.0

Confluence Server >= 8.0.0 < 8.0.0

Confluence Data Center < 8.0.0 < 8.0.0

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

a private user
.