V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2023-22518
CVE
Critical KEVConfirmedExploit available

All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability…

CVSS
9.8
Critical
EPSS
1.00
p100
Published
2023-01-01
Updated
2023-11-07
Description

All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability.  Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

Tags · CWE
KEVPre-auth
CWE-285
CWE-863
CAPEC-1
CAPEC-5
CAPEC-13
CAPEC-17
CAPEC-39
CAPEC-45
CAPEC-51
CAPEC-59
CAPEC-60
CAPEC-76
CAPEC-77
CAPEC-87
CAPEC-104
CAPEC-127
CAPEC-402
CAPEC-647
CAPEC-668
Affected products
Confluence_data_center 1.0–7.19.16Confluence_data_center 7.20.0–8.3.4Confluence_data_center 8.4.0–8.4.4Confluence_data_center 8.5.0–8.5.3Confluence_data_center
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2023-01-01
Published
2023-11-07
Added to KEV
2023-11-07
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
1.000 · p100
Known exploited (KEV)
Yes
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-647 · CWE-285
└ via CAPEC-647 · CWE-285
└ via CAPEC-127 · CWE-285
└ via CAPEC-60 · CWE-285
└ via CAPEC-60 · CWE-285
└ via CAPEC-647 · CWE-285
└ via CAPEC-668 · CWE-285
└ via CAPEC-13 · CWE-285
Known exploits — Сканер-ВС
CVE-2023-22518
cisa · https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Enterprise
Affected software
ProductVendorStatus
confluence_data_center*Exploited
confluence_server*Exploited
Source databases
CVE
Related vulnerabilities