CVE-2023-22515

Status: Analyzed
Last modified: 16-02-2024
Published: 04-10-2023
9.8

SUMMARY CVE-2023-22515

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

Access CVSS3 CVE-2023-22515

Attack Complexity Attack Vector Privileges Required Scope User Interaction
LOW NETWORK NONE UNCHANGED NONE

Impact CVSS3 CVE-2023-22515

Confidentiality Integrity Availability
HIGH HIGH HIGH

Details CVE-2023-22515

EPSS 0.97276
EPSS % 0.99889
References
CWE NVD-CWE-noinfo
Vulnerable Configurations
  • cpe:2.3:a:atlassian:confluence_data_center:8.0.0:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_data_center:8.0.0:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_data_center:8.0.1:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_data_center:8.0.1:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_data_center:8.0.2:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_data_center:8.0.2:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_data_center:8.0.3:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_data_center:8.0.3:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_data_center:8.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_data_center:8.1.0:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_data_center:8.1.3:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_data_center:8.1.3:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_data_center:8.1.4:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_data_center:8.1.4:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_data_center:8.2.0:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_data_center:8.2.0:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_data_center:8.2.1:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_data_center:8.2.1:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_data_center:8.2.2:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_data_center:8.2.2:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_data_center:8.2.3:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_data_center:8.2.3:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_data_center:8.3.0:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_data_center:8.3.0:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_data_center:8.3.1:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_data_center:8.3.1:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_data_center:8.3.2:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_data_center:8.3.2:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_data_center:8.4.0:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_data_center:8.4.0:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_data_center:8.4.1:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_data_center:8.4.1:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_data_center:8.4.2:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_data_center:8.4.2:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_data_center:8.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_data_center:8.5.0:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_data_center:8.5.1:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_data_center:8.5.1:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_server:8.0.0:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_server:8.0.0:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_server:8.0.1:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_server:8.0.1:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_server:8.0.2:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_server:8.0.2:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_server:8.0.3:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_server:8.0.3:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_server:8.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_server:8.1.0:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_server:8.1.3:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_server:8.1.3:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_server:8.1.4:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_server:8.1.4:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_server:8.2.0:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_server:8.2.0:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_server:8.2.1:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_server:8.2.1:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_server:8.2.2:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_server:8.2.2:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_server:8.2.3:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_server:8.2.3:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_server:8.3.0:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_server:8.3.0:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_server:8.3.1:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_server:8.3.1:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_server:8.3.2:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_server:8.3.2:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_server:8.4.0:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_server:8.4.0:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_server:8.4.1:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_server:8.4.1:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_server:8.4.2:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_server:8.4.2:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_server:8.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_server:8.5.0:*:*:*:*:*:*:*
  • cpe:2.3:a:atlassian:confluence_server:8.5.1:*:*:*:*:*:*:*
    cpe:2.3:a:atlassian:confluence_server:8.5.1:*:*:*:*:*:*:*
CVSS3 Source nvd@nist.gov
CVSS3 Type Primary
CVSS3 Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

ATOM RSS Feed Link for CVE Vulnerabilities

CVE Data Propulsed by AKAOMA CyberSecurity