Critical RCE Flaw in Confluence Data Center and Server Created

Critical RCE Flaw in Confluence Data Center and Server Created

A critical security vulnerability has been identified in Confluence Data Center and Confluence Server, known as CVE-2023-22527.

This vulnerability is rated at the highest severity level (CVSS 10) due to its potential for allowing unauthenticated attackers to execute arbitrary code on vulnerable systems.

The vulnerability stems from a template injection flaw in outdated versions of Confluence Data Center and Confluence Server, specifically versions 8.0.x to 8.5.3 released before December 5, 2023, and version 8.4.5.

Critical RCE Flaw in Confluence Data Center and Server Created

Affected Systems

Affected Versions

To mitigate this risk, users of affected versions must immediately upgrade to the latest available version of Confluence Data Center or Confluence Server. Patching or workarounds are not considered effective solutions for this vulnerability.

Product Affected Versions
Confluence Data Center and Server 8.0.x
8.1.x
8.2.x
8.3.x
8.4.x
8.5.0-8.5.3

IoC’s

-

Recommended Solution(s)

-

Mitigations

Product Latest Versions
Confluence Data Center and Server 8.5.5 (LTS)
Confluence Data Center 8.7.2 (Data Center Only)

There are no known workarounds. To remediate this vulnerability, update each affected product installation to the latest version.

CVE / CWE

CVE-2023-22527

Related Website(s)

* Vulnerabilities with a CVSS 3.1 score between 7.0 and 8.9 are evaluated to be “high” whereas vulnerabilities with a CVSS 3.1 score between 9.0 and 10.0 are evaluated to be “critical”.