Critical Atlassian Confluence flaw with vulnerability score of 10 draws federal warning
The U.S. Cybersecurity and Infrastructure Agency, the Federal Bureau of Investigation and the Multi-State Information Sharing and Analysis Center today released a Cybersecurity Advisory over a recently disclosed vulnerability in Atlassian Corp.’s Confluence Data Center and Server that opens the door to malicious cyber threat actors.
Tracked as CVE-2023-22515, the vulnerability has a Common Vulnerabilities and Exposure score of 10, the highest possible rating. The vulnerability is a critical Broken Access Control vulnerability affecting versions of Atlassian Confluence Data Center and Server ranging from 8.0.0 through to 8.5.1.
Using the vulnerability, unauthenticated remote threat actors can create unauthorized Confluence administrator accounts and access Confluence instances. With the access, threat actors can change the Confluence server’s configuration to indicate the setup is not complete and use the /setup/setupadministrator.action endpoint to create a new administrator user. The vulnerability is said to be triggered via a request on the unauthenticated /server-info.action endpoint.