EXPOSURES › CVE-2023-22527
CVE-2023-22527
CRITICAL ⌖ ON CISA KEV · EXPLOITEDUnauthenticated OGNL template injection in Atlassian Confluence Data Center and Server allows remote code execution.
An unauthenticated OGNL template injection flaw in Atlassian Confluence Data Center and Server enables remote code execution, allowing attackers to execute arbitrary commands without authentication. This is a critical failure because it directly enables remote code execution (RCE), which is a primary vector for ransomware and data breaches. DIB organizations must ensure Confluence is patched immediately and assess for compromise, as this vulnerability was actively exploited in the wild and linked to ransomware campaigns.
Shame score — A critical, unauthenticated RCE vulnerability in a widely deployed collaboration platform was actively exploited in the wild and linked to ransomware, demonstrating severe negligence in patching and threat monitoring.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.