Article Details
Scrape Timestamp (UTC): 2023-10-31 11:18:18.834
Source: https://thehackernews.com/2023/10/atlassian-warns-of-new-critical.html
Original Article Text
Click to Toggle View
Atlassian Warns of New Critical Confluence Vulnerability Threatening Data Loss. Atlassian has warned of a critical security flaw in Confluence Data Center and Server that could result in "significant data loss if exploited by an unauthenticated attacker." Tracked as CVE-2023-22518, the vulnerability is rated 9.1 out of a maximum of 10 on the CVSS scoring system. It has been described as an instance of "improper authorization vulnerability." All versions of Confluence Data Center and Server are susceptible to the bug, and it has been addressed in the following versions - That said, the Australian company emphasized that "there is no impact to confidentiality as an attacker cannot exfiltrate any instance data." No other details about the flaw and the exact method by which an adversary can take advantage of it have been made available, likely owing to the fact that doing so could enable threat actors to devise an exploit. Atlassian is also urging customers to take immediate action to secure their instances, recommending those that are accessible to the public internet be disconnected until a patch can be applied. What's more, users who are running versions that are outside of the support window are advised to upgrade to a fixed version. Atlassian Cloud sites are not affected by the issue. While there is no evidence of active exploitation in the wild, previously discovered shortcomings in the software, including the recently publicized CVE-2023-22515, have been weaponized by threat actors.
Daily Brief Summary
Atlassian has identified a significant security flaw (CVE-2023-22518) in Confluence Data Center and Server, warning that it has the potential for significant data loss if exploited by an unauthenticated attacker.
The bug holds a severity rating of 9.1 out of a maximum 10 on the CVSS scoring system and is categorized as an "improper authorization vulnerability."
All versions of Confluence Data Center and Server are potentially at risk, though Atlassian has taken steps to address the bug in several versions.
Atlassian advises that the flaw doesn't impact confidentiality, as attackers cannot exfiltrate any instance data. Detailed information about the flaw has not been released to prevent assisting potential threat actors.
Customers are urged to secure their instances, particularly those accessible to the public internet, and recommended to disconnect until a patch can be applied. Unsupported versions should upgrade to a fixed version.
There is currently no evidence of active exploitation of the flaw, however, past vulnerabilities like CVE-2023-22515 have been weaponized by threat actors. Atlassian Cloud sites are not affected by this issue.