{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aatlassianconfluence_server/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*","cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2023-22515"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-SPAREACK-CVE-2023-22515-NSE\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":[],"_cs_severities":["critical"],"_cs_tags":["confluence","cve-2023-22515","privilege-escalation","vulnerability"],"_cs_type":"threat","_cs_vendors":["Atlassian"],"content_html":"\u003cp\u003eCVE-2023-22515 is a critical vulnerability in Atlassian Confluence Data Center and Server that allows an unauthenticated attacker to create administrator accounts. This vulnerability impacts Confluence Data Center and Server versions before 7.19.16, from 7.20.0 before 8.3.4, from 8.4.0 before 8.4.4, from 8.5.0 before 8.5.2. Exploitation involves sending a specially crafted HTTP GET request to the \u003ccode\u003e/server-info.action\u003c/code\u003e endpoint with a modified \u003ccode\u003ebootstrapStatusProvider.applicationConfig.setupComplete\u003c/code\u003e parameter. Successful exploitation allows attackers to bypass authentication and gain administrative control, potentially leading to data breaches, code execution, or denial of service. Observed exploitation began in October 2023, shortly after the public disclosure of the vulnerability and a proof-of-concept exploit.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker sends an HTTP GET request to \u003ccode\u003e/server-info.action\u003c/code\u003e endpoint on a vulnerable Confluence server.\u003c/li\u003e\n\u003cli\u003eThe GET request includes a modified parameter \u003ccode\u003ebootstrapStatusProvider.applicationConfig.setupComplete\u003c/code\u003e set to \u003ccode\u003efalse\u003c/code\u003e or \u003ccode\u003e0\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe Confluence server incorrectly processes the request due to the vulnerability.\u003c/li\u003e\n\u003cli\u003eThe attacker bypasses authentication checks.\u003c/li\u003e\n\u003cli\u003eThe attacker gains access to administrative functionalities of the Confluence server.\u003c/li\u003e\n\u003cli\u003eThe attacker creates a new administrator account.\u003c/li\u003e\n\u003cli\u003eThe attacker logs in to the Confluence server using the newly created administrator account.\u003c/li\u003e\n\u003cli\u003eThe attacker gains complete control over the Confluence server, enabling data exfiltration, code execution, or further malicious activities.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2023-22515 allows attackers to gain full administrative control of vulnerable Atlassian Confluence servers. This can lead to complete data breaches, where sensitive information stored within Confluence is exposed. Attackers can also use their administrative privileges to install malware, pivot to other systems within the network, or cause a denial of service. Numerous organizations across various sectors have been targeted, with the vulnerability actively exploited in the wild.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the Sigma rule \u003ccode\u003eConfluence CVE-2023-22515 Trigger Vulnerability\u003c/code\u003e to your SIEM to detect exploitation attempts based on specific URL patterns and HTTP status codes.\u003c/li\u003e\n\u003cli\u003eEnable web server logging and ensure that the logs are being ingested into your SIEM.\u003c/li\u003e\n\u003cli\u003eApply the latest patches for Atlassian Confluence to remediate CVE-2023-22515 on all affected servers.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for suspicious HTTP requests to the \u003ccode\u003e/server-info.action\u003c/code\u003e endpoint, as detected by the \u003ccode\u003eConfluence CVE-2023-22515 Trigger Vulnerability\u003c/code\u003e rule.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T00:20:31Z","date_published":"2024-01-23T12:00:00Z","id":"https://feed.craftedsignal.io/briefs/2024-01-confluence-cve-2023-22515/","summary":"Detection of CVE-2023-22515 exploitation attempts targeting Atlassian Confluence servers by sending crafted HTTP requests to specific vulnerable endpoints, potentially leading to unauthorized access and privilege escalation.","title":"Atlassian Confluence CVE-2023-22515 Exploitation Attempt","url":"https://feed.craftedsignal.io/briefs/2024-01-confluence-cve-2023-22515/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}