Atlassian has patched a critical vulnerability (CVE-2023-22527) in Confluence Data Center and Confluence Server that could lead to remote code execution.
The good news is that the flaw was fixed in early December 2023 with the release of versions 8.5.4 LTS (Data Center and Server) and 8.6.0 and 8.7.1 (only Data Center), so some customers have already upgraded to those or to later versions. The bad news is that some customers haven’t.
Atlassian hasn’t mentioned whether the vulnerability is being actively exploited, but has said that customers “must take immediate action to protect their Confluence instances.”
About CVE-2023-22527
CVE-2023-22527 is a template injection vulnerability that allows an unauthenticated attacker to achieve RCE on an affected version of Confluence Data Center and Confluence Server: 8.0.x, 8.1.x, 8.2.x, 8.3.x, 8.4.x, and 8.5.0-8.5.3. There is no available workaround.
“Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular updates,” the company noted today (i.e., more than a month after releasing those updates).
Atlassian Cloud instances are not affected by this vulnerability, and neither is Confluence version 7.19.x.
Additional advice for customers
Vulnerable Confluence instances have been preferred targets of various threat actors over the years.
“If the Confluence instance cannot be accessed from the internet the risk of exploitation is reduced, but not completely mitigated,” the company added, and again “strongly recommended” upgrading to the latest version available.
If updating is impossible at this time, customers should take their system off the internet immediately, back up the data of the instance to a secure location outside of the Confluence instance, and engage their local security team to review for any potential malicious activity.
Unfortunately, Atlassian did not share possible indicators of compromise, as “the possibility of multiple entry points, along with chained attacks, makes it difficult to list [them all].”