PT-2023-5694 · Atlassian · Confluence
CVE-2023-22515
·
Published
2023-09-14
·
Updated
2026-09-07
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Confluence Data Center and Confluence Server versions 8.0.0 through 8.5.1
Description
Broken access control in publicly accessible instances allows unauthenticated remote attackers to create unauthorized administrator accounts and gain full control of the system. The issue occurs because an attacker can force the application into Setup Mode by manipulating the
bootstrapStatusProvider.applicationConfig.setupComplete parameter via an HTTP request to the /server-info.action endpoint. Once in Setup Mode, the attacker can use the /setup/setupadministrator.action endpoint to create a new administrator account and the /setup/finishsetup.action endpoint to complete the process. Real-world exploitation of this issue has been reported by customers.Recommendations
Upgrade Confluence Data Center and Confluence Server to versions 8.3.3, 8.4.3, or 8.5.2 or later.
As a temporary mitigation, restrict access to the
/setup/* endpoints using the Confluence configuration file or external security tools.Exploit
Fix
DoS
Improper Access Control
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Confluence