PT-2024-1275 · Atlassian · Confluence

·

CVE-2023-22526

·

Published

2024-01-15

·

Updated

2024-01-22

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Confluence Data Center and Server versions 7.19.0 through 7.19.16 Confluence Data Center and Server versions 8.5.0 through 8.5.4 Confluence Data Center versions 8.7.0 through 8.7.1
Description The issue is related to insufficient input validation, allowing a remote attacker to execute arbitrary code. This has a high impact on confidentiality, integrity, and availability, and requires no user interaction. The vulnerability was discovered by m1sn0w and reported via the Bug Bounty program.
Recommendations For Confluence Data Center and Server version 7.19: Upgrade to a release 7.19.17, or any higher 7.19.x release For Confluence Data Center and Server version 8.5: Upgrade to a release 8.5.5 or any higher 8.5.x release For Confluence Data Center version 8.7: Upgrade to a release 8.7.2 or any higher release

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00701
CVE-2023-22526

Affected Products

Confluence