Skip to content
COOEY

EXPOSURES › CVE-2023-22527

CVE-2023-22527

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-01-24 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-22527 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Unauthenticated OGNL template injection in Atlassian Confluence Data Center and Server allows remote code execution.

An unauthenticated OGNL template injection flaw in Atlassian Confluence Data Center and Server enables remote code execution, allowing attackers to execute arbitrary commands without authentication. This is a critical failure because it directly enables remote code execution (RCE), which is a primary vector for ransomware and data breaches. DIB organizations must ensure Confluence is patched immediately and assess for compromise, as this vulnerability was actively exploited in the wild and linked to ransomware campaigns.

Shame score — A critical, unauthenticated RCE vulnerability in a widely deployed collaboration platform was actively exploited in the wild and linked to ransomware, demonstrating severe negligence in patching and threat monitoring.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.