CVE-2023-22515
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- January 01, 2023
- Published Date
- October 04, 2023
- Last Updated
- September 13, 2024
- Vendor
- Atlassian
- Product
- Confluence Data Center, Confluence Server
- Description
- Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.
CVSS Scores
CVSS v3.0
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC Information
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- total
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2023-10-05 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/atlassian_confluence_rce_cve_2023_22515.rb | 2025-04-29 11:01:20 UTC |
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-22515.yaml | 2025-04-26 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
atlassian_confluence_rce_cve_2023_22515
Type: metasploit • Created: Unknown
spareack/CVE-2023-22515-NSE
Type: github • Created: 2024-07-18 19:55:59 UTC • Stars: 4
rxerium/CVE-2023-22515
Type: github • Created: 2024-02-24 16:04:35 UTC • Stars: 2
LucasPDiniz/CVE-2023-22515
Type: github • Created: 2023-11-08 05:18:30 UTC • Stars: 2
joaoviictorti/CVE-2023-22515
Type: github • Created: 2023-10-22 23:37:56 UTC • Stars: 3
youcannotseemeagain/CVE-2023-22515_RCE
Type: github • Created: 2023-10-20 08:23:47 UTC • Stars: 19
Le1a/CVE-2023-22515
Type: github • Created: 2023-10-13 05:18:54 UTC • Stars: 6
sincere9/CVE-2023-22515
Type: github • Created: 2023-10-12 02:41:23 UTC • Stars: 25
kh4sh3i/CVE-2023-22515
Type: github • Created: 2023-10-11 11:21:47 UTC • Stars: 4
ad-calcium/CVE-2023-22515
Type: github • Created: 2023-10-11 08:42:17 UTC • Stars: 107
Chocapikk/CVE-2023-22515
Type: github • Created: 2023-10-10 21:40:09 UTC • Stars: 133
j3seer/CVE-2023-22515-POC
Type: github • Created: 2023-10-10 18:45:10 UTC • Stars: 8
ErikWynter/CVE-2023-22515-Scan
Type: github • Created: 2023-10-06 20:29:44 UTC • Stars: 75