A critical security vulnerability has been identified in Confluence Data Center and Confluence Server, known as CVE-2023-22527.
This vulnerability is rated at the highest severity level (CVSS 10) due to its potential for allowing unauthenticated attackers to execute arbitrary code on vulnerable systems.
The vulnerability stems from a template injection flaw in outdated versions of Confluence Data Center and Confluence Server, specifically versions 8.0.x to 8.5.3 released before December 5, 2023, and version 8.4.5.
Affected Systems
Affected Versions
To mitigate this risk, users of affected versions must immediately upgrade to the latest
available version of Confluence Data Center or Confluence Server. Patching or
workarounds are not considered effective solutions for this vulnerability.
Product | Affected Versions |
---|---|
Confluence Data Center and Server |
8.0.x 8.1.x 8.2.x 8.3.x 8.4.x 8.5.0-8.5.3 |
IoC’s
-
Recommended Solution(s)
-
Mitigations
Product | Latest Versions |
---|---|
Confluence Data Center and Server | 8.5.5 (LTS) |
Confluence Data Center | 8.7.2 (Data Center Only) |
There are no known workarounds. To remediate this vulnerability, update each affected product installation to the latest version.
CVE / CWE
CVE-2023-22527
Related Website(s)
* Vulnerabilities with a CVSS 3.1 score between 7.0 and 8.9 are evaluated to be “high” whereas vulnerabilities with a CVSS 3.1 score between 9.0 and 10.0 are evaluated to be “critical”.
+90 216 504 53 32
Aydınevler Mahallesi,İsmet İnönü Cadddesi,Küçükyalı Ofis Park A Blok,No:20/1 Maltepe İstanbul
+90 312 235 44 51
You can register to our newsletter on the home page to be instantly informed about security vulnerabilities.