CVE-2023-22518
⚡ CISA KEV🔐 RansomwarePublished: —Modified: —Vendor: AtlassianProduct: Confluence Data Center and Server
—
CVSS v3
100.0%
EPSS
⚡ Added to KEV on 2023-11-07 · Federal agencies must remediate by 2023-11-28
Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.
💣 Public Exploits0
From Exploit-DB
No public exploits in Exploit-DB.
🔍 Sigma Detection Rules4
Rules tagged with this CVE
| high | CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Linux) | linux | — |
| medium | CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Windows) | windows | — |
| medium | CVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Proxy) | — | — |
| medium | CVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Webserver) | — | — |
🛠️ Patch Details2
Affected/fixed versions from threat intel reports
📰 Threat Intel Coverage9
Digest reports mentioning this CVE
| MFT Exploitation and Adversary Operations | Huntress | huntress | 2023-11-29 |
| Critical Vulnerability: SysAid CVE-2023-47246 | Huntress | huntress | 2023-11-10 |
| Confluence to Cerber: Exploitation of CVE-2023-22518 | Huntress | huntress | 2023-11-07 |
| Critical Vuln: Apache ActiveMQ CVE-2023-46604 Exploited | Huntress | huntress | 2023-11-02 |
| Critical Vuln: WebP Heap Buffer Overflow CVE-2023-4863 | Huntress | huntress | 2023-09-28 |
| Everything We Know About CVE-2023-23397 | Huntress | huntress | 2023-03-17 |
| Veeam Backup & Replication CVE-2023-27532 Response | Huntress | huntress | 2023-03-13 |
| Investigating Intrusions From Intriguing Exploits | Huntress | huntress | 2023-02-08 |
| Rapid Response: Mass Exploitation of On-Prem Exchange Servers | Huntress | huntress | 2021-03-03 |
📎 References0
No reference URLs.