HTTP: Atlassian Confluence Data Center and Server Broken Access Control

This signature detects attempts to exploit a known vulnerability against Atlassian Confluence Data Center and Server. A successful attack can lead to elevation of privilege and arbitrary code execution.

Extended Description

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

Affected Products

Atlassian confluence_data_center

References

CVE: CVE-2023-22515

Short Name
HTTP:CTS:ATLSN-SRVR-BAC
Severity
Critical
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Access Atlassian Broken CVE-2023-22515 Center Confluence Control Data Server and
Release Date
10/13/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3646
False Positive
Unknown
Vendors

Atlassian

Found a potential security threat?