bitvoodoo Advisories
Space shortcuts
Space Tools
bitvoodoo Advisories BVADVIS

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


Warning

This is a public space:

For the draft, please restrict the page during creation and
remove this warning when page is published



English

Contents

Table of Contents


Page properties


Date

 

Product
  • Confluence Data Center

  • Confluence Server

Vulnerabilitycritical
CVECVE-2023-22527
Official link




English

Dear customer,

On the 16th of January 2024, Atlassian issued a Security Advisory for Confluence Server & Confluence Data Center. The Cloud versions of the applications as well as other Atlassian products are not affected.

What you need to know

Atlassian has discovered that a template injection vulnerability on out-of-date versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected version.

Customers using an affected version must take immediate action.

Please NOTE: Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.

Affected Versions

Info


ProductAffected Versions
Confluence Data Center and Server
  • 8.0.x

  • 8.1.x

  • 8.2.x

  • 8.3.x

  • 8.4.x

  • 8.5.0-8.5.3




What should I do?

Localtab Group


Localtab
activetrue
titleConfluence Server & Data Center
tabIconbvicon-server

You use Confluence Data Center and Server

Update

If you are on an out-of-date version, you must immediately patch. 

Atlassian recommends that you patch each of your affected installations to the latest version available.

The listed Fixed Versions are no longer the most up-to-date and do not protect your instance from other non-critical vulnerabilities as outlined in Atlassian’s January Security Bulletin.

Product

Fixed Versions

Latest Versions

Confluence Data Center and Server

  • 8.5.4 (LTS)

  • 8.5.5 (LTS)

Confluence Data Center

  • 8.6.0 (Data Center Only)

  • 8.7.1 (Data Center Only)

  • 8.7.2 (Data Center Only)

Mitigation

There are no known workarounds. To remediate this vulnerability, update each affected product installation to the latest version.



Localtab
titleAtlassian Confluence Cloud
tabIconbvicon-cloud

You use Confluence Cloud

Tip

You are not affected by this Security Advisory. No need for action.



Localtab
titlebitvoodoo Cloud
tabIconbvicon-cloud

You use Confluence on servers operated by bitvoodoo


Tip

You are not affected by this Security Advisory. No need for action.




Support

If you still have questions or concerns regarding this advisory, please contact the bitvoodoo support via support.bitvoodoo.ch.



bitvoodoo Advisories BVADVIS