Skip to content
Threat Feed

Tag

Confluence

4 briefs RSS
critical threat

Atlassian Confluence CVE-2023-22515 Exploitation Attempt

Detection of CVE-2023-22515 exploitation attempts targeting Atlassian Confluence servers by sending crafted HTTP requests to specific vulnerable endpoints, potentially leading to unauthorized access and privilege escalation.

PoC confluence cve-2023-22515 privilege-escalation vulnerability
2r 1t 1c updated
critical advisory

Confluence Pre-Auth RCE via OGNL Injection (CVE-2023-22527)

Attackers are exploiting CVE-2023-22527, a critical remote code execution vulnerability in Atlassian Confluence Server and Data Center, by sending crafted POST requests to a specific endpoint to inject and execute arbitrary OGNL expressions, potentially leading to complete system compromise.

PoC CVE-2023-22527 confluence rce ognlinjection
2r 1t 1c updated
critical advisory

Metasploit Exploitation via Malicious Confluence Plugin

A Metasploit module exploits Atlassian Confluence servers by deploying a malicious Java plugin that downloads Meterpreter, granting the attacker full control over the compromised system.

Confluence Data Center +4 confluence metasploit meterpreter plugin exploitation attack
2r 3t
critical advisory

Confluence Unauthenticated Remote Code Execution (CVE-2022-26134)

Exploitation of CVE-2022-26134, an unauthenticated remote code execution vulnerability in Atlassian Confluence, allows attackers to execute arbitrary code on vulnerable servers, potentially leading to complete system compromise.

PoC confluence rce cve-2022-26134 webserver
2r 4t 1c 2i updated