KEVIntel
10.0
CVSS
Critical

CVE-2023-22527

PUBLISHED

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an...

Exploited in the wild Used in malware Remote Low complexity No user interaction
Vendor
Atlassian
Product
Confluence Data Center, Confluence Server
Published
Jan 16, 2024
EPSS

Description

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.

cisa malware ransomware nuclei_scanner metasploit

CVSS scores

CVSS v3.0 10.0 Critical

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2024-01-24 00:00:00 UTC · Source

Used in malware

Recorded 2024-01-24 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Jan 24, 2024

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

atlassian_confluence_rce_cve_2023_22527

metasploit · Created Unknown

Metasploit module for CVE-2023-22527

M0untainShley/CVE-2023-22527-MEMSHELL

github · Created 2024-02-26 02:34:44 UTC · 40 stars

confluence CVE-2023-22527 漏洞利用工具,支持冰蝎/哥斯拉内存马注入,支持设置 http 代理

Boogipop/CVE-2023-22527-Godzilla-MEMSHELL

github · Created 2024-02-11 16:46:55 UTC · 74 stars

CVE-2023-22527 内存马注入工具

adminlove520/CVE-2023-22527

github · Created 2024-01-25 10:52:39 UTC · 5 stars

CVE-2023-22527 - RCE (Remote Code Execution) Vulnerability In Confluence Data Center and Confluence Server PoC

Privia-Security/CVE-2023-22527

github · Created 2024-01-24 21:29:59 UTC · 4 stars

CVE-2023-22527

yoryio/CVE-2023-22527

github · Created 2024-01-24 04:44:59 UTC · 4 stars

Exploit for CVE-2023-22527 - Atlassian Confluence Data Center and Server

RevoltSecurities/CVE-2023-22527

github · Created 2024-01-23 17:07:15 UTC · 10 stars

An Exploitation tool to exploit the confluence server that are vulnerable to CVE-2023-22527 leads to RCE

Chocapikk/CVE-2023-22527

github · Created 2024-01-23 10:55:28 UTC · 10 stars

Atlassian Confluence - Remote Code Execution

Niuwoo/CVE-2023-22527

github · Created 2024-01-23 09:28:53 UTC · 2 stars

POC

C1ph3rX13/CVE-2023-22527

github · Created 2024-01-23 08:53:46 UTC · 4 stars

Atlassian Confluence - Remote Code Execution (CVE-2023-22527)

Vozec/CVE-2023-22527

github · Created 2024-01-23 08:06:15 UTC · 12 stars

This repository presents a proof-of-concept of CVE-2023-22527

VNCERT-CC/CVE-2023-22527-confluence

github · Created 2024-01-23 07:10:55 UTC · 19 stars

[Confluence] CVE-2023-22527 realworld poc

Manh130902/CVE-2023-22527-POC

github · Created 2024-01-23 02:17:36 UTC · 21 stars

A critical severity Remote Code Execution (RCE) vulnerability (CVE-2023-22527) was discovered in Confluence Server and Data Center.

thanhlam-attt/CVE-2023-22527

github · Created 2024-01-22 19:02:59 UTC · 5 stars

Drun1baby/CVE-2023-22527

github · Created 2024-01-22 11:38:55 UTC · 2 stars

ga0we1/CVE-2023-22527_Confluence_RCE

github · Created 2024-01-17 10:21:00 UTC · 1 stars

CVE-2023-22527 - RCE (Remote Code Execution) Vulnerability In Confluence Data Center and Confluence Server PoC

Sudistark/patch-diff-CVE-2023-22527

github · Created 2024-01-16 13:50:49 UTC · 3 stars

Avento/CVE-2023-22527_Confluence_RCE

github · Created 2024-01-16 08:46:21 UTC · 24 stars

CVE-2023-22527 - RCE (Remote Code Execution) Vulnerability In Confluence Data Center and Confluence Server PoC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit