CVE-2023-22527 - Atlassian Confluence Data Center and Server
AI Vulnerability ContextA template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian...
Overview
A source-backed snapshot of this vulnerability.
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action.
Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.
Vulnerability status
How serious this vulnerability is and whether it is known to be exploited.
- CVE ID
- CVE-2023-22527
- Vendor/project
- Atlassian
- Product
- Confluence Data Center and Server
- Vulnerability name
- Atlassian Confluence Data Center and Server Template Injection Vulnerability
- Date added
- 2024-01-24
- Due date
- 2024-02-14
- Known ransomware campaign use
- Known
- CVSS v3
- 9.8
Exploit context
What the vulnerability is about.
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action.
Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.
Source evidence
Original public records and references for this page.
Original source
Original source links
Open the public records and source datasets used for this page.
