Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-22515


Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.


Published

2023-10-04T14:15:10.440

Last Modified

2025-02-09T20:49:55.073

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application atlassian confluence_data_center < 8.3.3 Yes
Application atlassian confluence_data_center < 8.4.3 Yes
Application atlassian confluence_data_center < 8.5.2 Yes
Application atlassian confluence_server < 8.3.3 Yes
Application atlassian confluence_server < 8.4.3 Yes
Application atlassian confluence_server < 8.5.2 Yes

References