CVE-2023-22515

Thursday, April 4 at 10 AM

CVE-2023-22515

CVE-2023-22515 is an unauthenticated critical severity vulnerability allowing remote attackers to create unauthorized Confluence Administrator accounts and access Confluence instances.

CVE Score : 9.8

98.0%

Affected Version

  • Confluence Data Center and Confluence Server
  • 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.1.0, 8.1.1, 8.1.3, 8.1.4, 8.2.0, 8.2.1, 8.2.2, 8.2.3, 8.3.0, 8.3.1, 8.3.2, 8.4.0, 8.4.1, 8.4.2, 8.5.0, 8.5.1

Patched Version

  • Confluence Data Center and Confluence Server
  • 8.3.3 or later, 8.4.3 or later, 8.5.2 (Long Term Support release) or later

Different Search Engine Query To Find Internet Exposed Instances:

#Search QuerySearch Engine
1http.favicon.hash:-305179312Shodan
2http.component:"Atlassian Confluence"Shodan
3app="ATLASSIAN-Confluence"Fofa

A Shodan search for "Atlassian Confluence" reveals around 120247 instances exposed to the internet.

Get Version Information:

How To Find Server Version Information:

  • Take IP from the above shodan query
  • Append following string with IP address: /server-info.action

Example: http://10[.]10.20.30:8111/server-info.action

  • It will redirect you to "/login.action?" page.
  • Check the source code and you will able to find Version infroamtion by searching for following string:
  • "ajs-version-number"
  • Compare the version with above mentioned affected version list.

-- Team ZeroDayNinjas --

Recent Advisories

CVE-2023-22515

Confluence Data Center and Server ZeroDay

Broken Access Control Vulnerability in Confluence Data Center and Server

CVE-2024-27198

TeamCity ZeroDay

In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

CVE-2024-2879

LayerSlider WordPress ZeroDay

Unauthenticated SQL Injection in LayerSlider