CVE-2023-22515 – Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
https://notcve.org/view.php?id=CVE-2023-22515
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue. Atlassian ha sido informado de un problema informado por un puñado de clientes en el que atacantes externos pueden haber explotado una vulnerabilidad previamente desconocida en instancias de Confluence Data Center and Server de acceso público para crear cuentas de administrador de Confluence no autorizadas y acceder a instancias de Confluence. Los sitios de Atlassian Cloud no se ven afectados por esta vulnerabilidad. • https://github.com/Chocapikk/CVE-2023-22515 https://github.com/Le1a/CVE-2023-22515 https://github.com/joaoviictorti/CVE-2023-22515 https://github.com/kh4sh3i/CVE-2023-22515 https://github.com/CalegariMindSec/Exploit-CVE-2023-22515 https://github.com/s1d6point7bugcrowd/CVE-2023-22515-check https://github.com/ad-calcium/CVE-2023-22515 https://github.com/ErikWynter/CVE-2023-22515-Scan https://github.com/sincere9/CVE-2023-22515 https://github.com/j3seer/CVE-2023-22515-POC https • CWE-20: Improper Input Validation •