Back to overview

CVE-2023-22527

CRITICAL KEV CISA Exploitation: ACTIVE Ransomware noto
10.0
CVSS 3.0
Description
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.

Metadata

CVE ID
CVE-2023-22527
State
PUBLISHED
Assigner
atlassian
Reserved
2023-01-01 00:01 UTC
Published
2024-01-16 05:00 UTC
Last updated
2025-10-21 23:05 UTC
Primary CWE
CWE-74
CWE-74 Improper Neutralization of Special Elements in Output…
Vendor / Product
Atlassian / Confluence Data Center
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
yes
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
Atlassian Confluence Data Center and Server Template Injection Vulnerability
Vendor
Atlassian
Product
Confluence Data Center and Server
Added to KEV
2024-01-24
Due date
2024-02-14
Ransomware
Known use
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CISA description
Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.
Affected products (2)
VendorProductPlatformVersions
Atlassian Confluence Data Center < 8.0.0, >= 8.0.0, >= 8.1.0, >= 8.2.0 …
Atlassian Confluence Server < 8.0.0, >= 8.0.0, >= 8.1.0, >= 8.2.0 …
Weakness (CWE)
CWESourceDescription
cna RCE (Remote Code Execution)
CWE-74 adp CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview