PT-2023-5694 · Atlassian · Confluence

CVE-2023-22515

·

Published

2023-09-14

·

Updated

2026-09-07

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Confluence Data Center and Confluence Server versions 8.0.0 through 8.5.1
Description Broken access control in publicly accessible instances allows unauthenticated remote attackers to create unauthorized administrator accounts and gain full control of the system. The issue occurs because an attacker can force the application into Setup Mode by manipulating the bootstrapStatusProvider.applicationConfig.setupComplete parameter via an HTTP request to the /server-info.action endpoint. Once in Setup Mode, the attacker can use the /setup/setupadministrator.action endpoint to create a new administrator account and the /setup/finishsetup.action endpoint to complete the process. Real-world exploitation of this issue has been reported by customers.
Recommendations Upgrade Confluence Data Center and Confluence Server to versions 8.3.3, 8.4.3, or 8.5.2 or later. As a temporary mitigation, restrict access to the /setup/* endpoints using the Confluence configuration file or external security tools.

Exploit

Fix

DoS

Improper Access Control

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-06364
BDU:2026-14138
CVE-2023-22515

Affected Products

Confluence