2023-10-04 16:00:28 +00:00
{
"id" : "CVE-2023-22515" ,
"sourceIdentifier" : "security@atlassian.com" ,
"published" : "2023-10-04T14:15:10.440" ,
2023-10-10 20:00:29 +00:00
"lastModified" : "2023-10-10T19:22:02.770" ,
"vulnStatus" : "Analyzed" ,
"cisaExploitAdd" : "2023-10-05" ,
"cisaActionDue" : "2023-10-26" ,
"cisaRequiredAction" : "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable." ,
"cisaVulnerabilityName" : "Atlassian Confluence Data Center and Server Privilege Escalation Vulnerability" ,
2023-10-04 16:00:28 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances.\n\nAtlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue. \n\nFor more details, please review the linked advisory on this CVE."
2023-10-10 20:00:29 +00:00
} ,
{
"lang" : "es" ,
"value" : "Atlassian ha sido informado de un problema por un pu\u00f1ado de clientes que atacantes externos pueden haber explotado una vulnerabilidad previamente desconocida en instancias de Confluence Data Center y Server de acceso p\u00fablico para crear cuentas de administrador de Confluence no autorizadas y acceder a instancias de Confluence. Los sitios de Atlassian Cloud no se ven afectados por esta vulnerabilidad. Si se accede a su sitio de Confluence a trav\u00e9s de un dominio atlassian.net, est\u00e1 alojado en Atlassian y no es vulnerable a este problema. Para obtener m\u00e1s detalles, revise el aviso vinculado sobre este CVE."
2023-10-04 16:00:28 +00:00
}
] ,
"metrics" : {
2023-10-10 20:00:29 +00:00
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 9.8 ,
"baseSeverity" : "CRITICAL"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 5.9
}
] ,
2023-10-04 16:00:28 +00:00
"cvssMetricV30" : [
{
"source" : "security@atlassian.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.0" ,
"vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 10.0 ,
"baseSeverity" : "CRITICAL"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 6.0
}
]
} ,
2023-10-10 20:00:29 +00:00
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-noinfo"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "8.0.0" ,
"versionEndExcluding" : "8.3.3" ,
"matchCriteriaId" : "85B2AD9F-CBA6-4559-9AE3-5F76A9EC3B7F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "8.4.0" ,
"versionEndExcluding" : "8.4.3" ,
"matchCriteriaId" : "38F9918D-6848-4CD6-8096-4FB48C23818B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "8.5.0" ,
"versionEndExcluding" : "8.5.2" ,
"matchCriteriaId" : "8D646BCF-214F-449D-AEEB-B253E8715394"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "8.0.0" ,
"versionEndExcluding" : "8.3.3" ,
"matchCriteriaId" : "970A3DA7-5114-4696-A93D-C3D5AFF5C6C5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "8.4.0" ,
"versionEndExcluding" : "8.4.3" ,
"matchCriteriaId" : "A2EB19CD-AE29-4775-91C5-05B01A96AC6C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "8.5.0" ,
"versionEndExcluding" : "8.5.2" ,
"matchCriteriaId" : "79229BE7-0AA0-4308-8BB2-8FB11E8B9AD7"
}
]
}
]
}
] ,
2023-10-04 16:00:28 +00:00
"references" : [
{
"url" : "https://confluence.atlassian.com/display/KB/FAQ+for+CVE-2023-22515" ,
2023-10-10 20:00:29 +00:00
"source" : "security@atlassian.com" ,
"tags" : [
"Vendor Advisory"
]
2023-10-04 16:00:28 +00:00
} ,
{
"url" : "https://confluence.atlassian.com/pages/viewpage.action?pageId=1295682276" ,
2023-10-10 20:00:29 +00:00
"source" : "security@atlassian.com" ,
"tags" : [
"Vendor Advisory"
]
2023-10-04 16:00:28 +00:00
} ,
{
"url" : "https://jira.atlassian.com/browse/CONFSERVER-92457" ,
2023-10-10 20:00:29 +00:00
"source" : "security@atlassian.com" ,
"tags" : [
"Issue Tracking" ,
"Permissions Required"
]
2023-10-04 16:00:28 +00:00
}
]
}