Atlassian warns of critical RCE flaw in older Confluence versions
ID: 9f67d6f3-f6f6-54bf-8d5d-eaa11af65a46
STIX ID: report--9f67d6f3-f6f6-54bf-8d5d-eaa11af65a46
Feed Name: Bleeping Computer
Threat Score
Atlassian Confluence Data Center and Server are affected by a critical template-injection remote code execution vulnerability (CVE-2023-22527, CVSS 10.0) impacting multiple 8.x release branches prior to the December 2023 fixes; Atlassian released patched builds (e.g., 8.5.4 LTS, 8.6.0, 8.7.1) and recommends updating as no mitigations or IoCs are available and out-of-support branches will not be patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
