bitvoodoo Advisories
Space shortcuts
Space Tools
bitvoodoo Advisories BVADVIS

Contents

Date

 

Product
  • Confluence Data Center

  • Confluence Server

Vulnerabilitycritical
CVECVE-2023-22527
Official linkhttps://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html

Dear customer,

On the 16th of January 2024, Atlassian issued a Security Advisory for Confluence Server & Confluence Data Center. The Cloud versions of the applications as well as other Atlassian products are not affected.

What you need to know

Atlassian has discovered that a template injection vulnerability on out-of-date versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected version.

Customers using an affected version must take immediate action.

Please NOTE: Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.

Affected Versions

ProductAffected Versions
Confluence Data Center and Server
  • 8.0.x

  • 8.1.x

  • 8.2.x

  • 8.3.x

  • 8.4.x

  • 8.5.0-8.5.3



What should I do?

You use Confluence Data Center and Server

Update

If you are on an out-of-date version, you must immediately patch. 

Atlassian recommends that you patch each of your affected installations to the latest version available.

The listed Fixed Versions are no longer the most up-to-date and do not protect your instance from other non-critical vulnerabilities as outlined in Atlassian’s January Security Bulletin.

Product

Fixed Versions

Latest Versions

Confluence Data Center and Server

  • 8.5.4 (LTS)

  • 8.5.5 (LTS)

Confluence Data Center

  • 8.6.0 (Data Center Only)

  • 8.7.1 (Data Center Only)

  • 8.7.2 (Data Center Only)

Mitigation

There are no known workarounds. To remediate this vulnerability, update each affected product installation to the latest version.


You use Confluence Cloud

You are not affected by this Security Advisory. No need for action.

You use Confluence on servers operated by bitvoodoo


You are not affected by this Security Advisory. No need for action.


Support

If you still have questions or concerns regarding this advisory, please contact the bitvoodoo support via support.bitvoodoo.ch.



bitvoodoo Advisories BVADVIS