CVE-2023-22515: Atlassian Confluence Data Center and Server Broken Access
Atlassian Confluence Data Center and Server Broken Access Control Vulnerability. Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.
- CISA KEV-listed (remediation due 2023-10-13)
- used in ransomware campaigns
- EPSS 99.2% (99.9% percentile)
- CVSS 9.8 critical
Detection rules
Related briefings
Linked threat actors
- Andariel machine-inferred link