Atlassian Security Update – 05 October 2023

Atlassian has released a security update to address a critical vulnerability across multiple products.

The addressed vulnerability could allow the remote attacker to gain elevated privileges on the system, caused by an error related to the /setup/* endpoints on Confluence instances allowing the creation of administrator accounts that can be used to access Confluence instances.

Atlassian Confluence Data Center and Server Privilege Escalation Vulnerability (CVE-2023-22515):

  • CVSS: 10
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Privileges

Affected Products:

  • Atlassian Confluence Server.
  • Atlassian Confluence Data Center.
Vulnerabilities

CVE-2023-22515

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Atlassian Security Update 

References