CVE-2023-22515 Details
Description
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.
A broken access control vulnerability has been identified in Atlassian Confluence Data Center and Server versions 8.0.0 through 8.3.2, 8.4.0 through 8.4.2, and 8.5.0 through 8.5.1. This vulnerability allows external attackers to create unauthorized Confluence administrator accounts on publicly accessible instances, granting them access to the Confluence environment. The issue arises from improper validation of input, which can be exploited to manipulate Java objects at runtime, ultimately leading to the creation of admin accounts and potential execution of malicious code via uploaded plugins.
Atlassian recommends upgrading to Confluence Data Center or Server versions 8.3.3, 8.4.3, or 8.5.2. If an immediate upgrade is not possible, restrict external network access to the affected instance and block access to the /setup/* endpoints. This can be done at the network layer or by modifying the Confluence web.xml file to include a security constraint that blocks these endpoints.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 9, 2023References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Atlassian Confluence Data Center and Server Broken Access Control Vulnerability | Oct 5, 2023 | Oct 13, 2023 | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Check all affected Confluence instances for evidence of compromise per vendor instructions and report any positive findings to CISA. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-20 | Improper Input Validation | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| atlassian confluence data center | >= 8.0.0, < 8.3.3 >= 8.4.0, < 8.4.3 >= 8.5.0, < 8.5.2 |
CPE
Remediation
| |
| atlassian confluence server | >= 8.0.0, < 8.3.3 >= 8.4.0, < 8.4.3 >= 8.5.0, < 8.5.2 |
CPE
Remediation
| |
Change History
17 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Mar 25, 2026 | Modified Analysis | [email protected] |
| Mar 25, 2026 | CVE Modified | CISA-ADP |
| Oct 24, 2025 | Modified Analysis | [email protected] |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Feb 9, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Sep 16, 2024 | Modified Analysis | [email protected] |
| Sep 13, 2024 | CVE Modified | CISA-ADP |
| May 14, 2024 | CVE Modified | [email protected] |
| Feb 16, 2024 | Modified Analysis | [email protected] |
| Oct 20, 2023 | CVE Modified | [email protected] |
| Oct 19, 2023 | CVE Modified | [email protected] |
| Oct 10, 2023 | Initial Analysis | [email protected] |