CVE-2023-22518KEV · OVERDUE

Atlassian Confluence Data Center and Server Improper Authorization Vulnerability

Critical · published October 31, 2023

Patch now

Confirmed exploited, and the score agrees

CVSS calls it critical at 10.0. It is confirmed in active exploitation. It sits in the 100.0th percentile for exploit probability.

1013
days past CISA
deadline
CVSS v3.0
10.0
EPSS
100%
Percentile
100.0
In the wild
Confirmed
What it is

🚨 An unauthenticated attacker can reset your Confluence instance and create an admin account — that’s like letting a stranger into your office and handing them the keys! 🔥 Think of it like leaving the front door of your office unlocked while you’re out. If someone just waltzes in, they could grab the office keys and access everything inside, including sensitive documents and confidential conversations. With this vulnerability, the attacker could gain complete control over your Confluence instance, leading to total loss of confidentiality, integrity, and availability. Imagine the chaos: unauthorized access to sensitive information, unexplained changes to documents, and even system downtime. Your data would be at the mercy of an intruder!

Put simply

Think of it like leaving the front door of your office unlocked while you’re out. If someone just waltzes in, they could grab the office keys and access everything inside, including sensitive documents and confidential conversations. This improper authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account, enabling them to perform any administrative action without restriction.

What to do

With this vulnerability, the attacker could gain complete control over your Confluence instance, leading to total loss of confidentiality, integrity, and availability. Imagine the chaos: unauthorized access to sensitive information, unexplained changes to documents, and even system downtime. Your data would be at the mercy of an intruder! To protect your Confluence installation, patch to the latest version immediately and review your access controls. Ensure that only authenticated users can perform administrative tasks and regularly audit your user accounts for any unauthorized access. 🛡️ You've got this! Follow these steps to secure your Confluence instance and keep your data safe from potential threats. 💪✨

The record
Technical detail
CVSS v3.0
10.0 · CRITICAL
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.99999 · 100.0th percentile
Published
2023-10-31T14:30Z
KEV added
2023-11-07 · due 2023-11-28
EPSS history
Timeline
  • 07 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 28
    kev
  • 31 OCT 14:30Z
    All versions of Confluence Data Center and Server are affected by this unexploited vulnerability
    cvelistv5