Security advisories

Maximum Severity Confluence Vulnerability (CVE-2023-22527)

January 17, 2024 | 1 MIN READ

Speak With A Security Expert Now

TALK TO AN EXPERT

THE THREAT

2024-01-22 Update: As of January 21st, there are reports of real-world exploitation of CVE-2023-22527

On January 16th, Atlassian disclosed a new critical Remote Code Execution (RCE) vulnerability that impacts Confluence Data Center and Confluence Server. The vulnerability, tracked as CVE-2023-22527 (CVSS: 10), allows a remote and unauthenticated threat actor to execute arbitrary code on impacted systems.

At this time, there is no indication of active exploitation of CVE-2023-22527. As this vulnerability has a maximum severity rating and enables unauthenticated RCE, it will attract significant attention from both security researchers and threat actors. The eSentire Threat Intelligence team assesses with high confidence that real-world exploitation will occur in the near future.

What we’re doing about it

What you should do about it

Additional information

It is critical that organizations apply the relevant Confluence security patches as soon as possible. As technical details surrounding the security patch are publicly available, threat actors are almost certainly attempting to reverse engineer the changes to develop an exploit. Due to these details, there is only a short time window for defenders to deploy the patches before exploitation occurs. The eSentire Threat Intelligence team was able to identify over 60,000 Confluence servers exposed to the internet; hundreds of these devices were confirmed to be exploitable via CVE-2023-22527.

Impacted Confluence Data Center and Confluence Server Versions:

It should be noted that CVE-2023-22527 does not impact Atlassian Cloud sites. Confluence sites, accessible via the Atlassian.net domain, are not vulnerable to exploitation.

References:

[1] https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html
[2] https://confluence.atlassian.com/kb/faq-for-cve-2023-22527-1332810917.html

View Most Recent Advisories