Security alert: privilege escalation vulnerability in Confluence Data Center and Server, CVE-2023-22515
ID: 3fcac2ff-a876-5dd4-a179-e30a983ef3e3
STIX ID: report--3fcac2ff-a876-5dd4-a179-e30a983ef3e3
Feed Name: Expel Blog
Threat Score
A critical privilege-escalation vulnerability (CVE-2023-22515) in Atlassian Confluence Data Center and Server versions 8.0–8.5.1 is being actively exploited to allow attackers to create administrative accounts on external-facing servers; Atlassian has released a patch and organizations are advised to upgrade/apply the patch and search for IOCs such as unexpected confluence-administrator group members or newly created user accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
