{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aatlassianconfluence_data_center8.7.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*","cpe:2.3:a:atlassian:confluence_data_center:8.7.0:*:*:*:*:*:*:*","cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2023-22527"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-PRIVIA-SECURITY-CVE-2023-22527\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":[],"_cs_severities":["critical"],"_cs_tags":["CVE-2023-22527","confluence","rce","ognlinjection"],"_cs_type":"advisory","_cs_vendors":["Atlassian"],"content_html":"\u003cp\u003eCVE-2023-22527 is a critical remote code execution vulnerability affecting Atlassian Confluence Data Center and Server. This vulnerability allows an unauthenticated attacker to execute arbitrary code on vulnerable instances. The vulnerability stems from a template injection flaw in the \u0026quot;/template/aui/text-inline.vm\u0026quot; endpoint, which allows for OGNL injection via specially crafted POST requests. Successful exploitation grants the attacker complete control over the Confluence server. Publicly available exploit code has increased the risk of widespread exploitation. Defenders should prioritize patching vulnerable systems and implementing detection mechanisms to identify exploitation attempts.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker sends a crafted POST request to the \u003ccode\u003e/template/aui/text-inline.vm\u003c/code\u003e endpoint on a vulnerable Confluence server.\u003c/li\u003e\n\u003cli\u003eThe POST request contains a malicious OGNL expression within the request body.\u003c/li\u003e\n\u003cli\u003eThe Confluence server processes the request without proper sanitization of the OGNL expression.\u003c/li\u003e\n\u003cli\u003eThe malicious OGNL expression is injected into the Velocity template engine.\u003c/li\u003e\n\u003cli\u003eThe Velocity template engine executes the injected OGNL expression.\u003c/li\u003e\n\u003cli\u003eThe attacker gains arbitrary code execution on the Confluence server.\u003c/li\u003e\n\u003cli\u003eThe attacker leverages code execution to install a webshell for persistent access.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the webshell to perform reconnaissance, move laterally within the network, and potentially exfiltrate sensitive data or deploy ransomware.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2023-22527 allows unauthenticated attackers to achieve remote code execution on affected Confluence servers. This can lead to complete system compromise, data breaches, and lateral movement within the victim's network. Given the widespread use of Confluence in enterprise environments, the impact of this vulnerability is potentially very high, and could affect thousands of organizations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the vendor-supplied patch for CVE-2023-22527 to all Confluence Server and Data Center instances immediately.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u003ccode\u003eConfluence Pre-Auth RCE via OGNL Injection CVE-2023-22527\u003c/code\u003e to your SIEM to detect exploitation attempts targeting the vulnerable endpoint.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for POST requests to \u003ccode\u003e/template/aui/text-inline.vm\u003c/code\u003e as identified by the URL IOC \u003ccode\u003e*/template/aui/text-inline.vm*\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eReview and restrict network access to Confluence servers to only authorized users and systems.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T01:47:46Z","date_published":"2024-01-09T10:00:00Z","id":"https://feed.craftedsignal.io/briefs/2024-01-confluence-cve-2023-22527/","summary":"Attackers are exploiting CVE-2023-22527, a critical remote code execution vulnerability in Atlassian Confluence Server and Data Center, by sending crafted POST requests to a specific endpoint to inject and execute arbitrary OGNL expressions, potentially leading to complete system compromise.","title":"Confluence Pre-Auth RCE via OGNL Injection (CVE-2023-22527)","url":"https://feed.craftedsignal.io/briefs/2024-01-confluence-cve-2023-22527/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:atlassian:confluence_data_center:8.7.0:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}