Threat intelligence report · CISA KEV

CVE-2023-22515: Atlassian Confluence Data Center and Server Broken Access Control Vulnerability

Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Check all affected Confluence instances for evidence of compromise per vendor instructions and report any positive findings to CISA.

· high severity · unattributed attribution

Evidence and provenance

Original source
CISA KEV report ↗
Published
2023-10-05T00:00:00Z
Confidence basis
No actor match
Record ID
7b3f8c0266b1a86cf4d1

Vulnerabilities

CVE-2023-22515

Use and citation

Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.