CVE-2023-22515: Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Check all affected Confluence instances for evidence of compromise per vendor instructions and report any positive findings to CISA.
· high severity · unattributed attribution
Evidence and provenance
- Original source
- CISA KEV report ↗
- Published
- 2023-10-05T00:00:00Z
- Confidence basis
- No actor match
- Record ID
7b3f8c0266b1a86cf4d1
Vulnerabilities
CVE-2023-22515
Use and citation
Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.