Tag: Atlassian

CISA, FBI urge admins to patch Atlassian Confluence immediately
News

CISA, FBI urge admins to patch Atlassian Confluence immediately

Network administrators were alerted today by CISA, FBI, and MS-ISAC to patch their Atlassian Confluence servers right away to prevent attacks that actively take advantage of a maximum severity vulnerability. This major privilege escalation problem, tracked as CVE-2023-22515, affects Confluence Data Center and Server 8.0.0 and later. Low-complexity attacks that don't require user input can remotely exploit it. Atlassian urged users to update their Confluence instances as quickly as possible to one of the corrected versions (i.e., 8.3.3 or later, 8.4.3 or later, or 8.5.2 or later) when it provided security patches on October 4. This was because the flaw had already been exploited in the wild as a zero-day. It was advised for those who were unable to upgrade to either terminate the ...
Atlassian patches critical Confluence zero-day exploited in attacks
News

Atlassian patches critical Confluence zero-day exploited in attacks

The Confluence Data Center and Server software from the Australian software company Atlassian contains a maximum severity zero-day vulnerability that has been used in attacks and was fixed by urgent security updates. Atlassian said it had been informed of a problem wherein "external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances." "This issue does not affect Atlassian Cloud sites. Your Confluence site is hosted by Atlassian and is not exposed to this problem if it can be accessed through an atlassian.net domain read more Atlassian patches critical Confluence zero-day exploited in attacks. Stay informed with th...