Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Nov 28, 2023

CVE-2023-22518

High
EPSS 94.4%CISA KEVRansomware
Atlassian/Confluence Data Center and Server

Description

Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.

EPSS — Exploit Probability

94.4%

Higher than 100.0% of all CVEs

Required Action

https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html; https://nvd.nist.gov/vuln/detail/CVE-2023-22518

Risk Assessment

CRITICAL
In CISA KEV
High EPSS
Ransomware

Details

Severity
High
EPSS
94.4%
CISA KEV
Yes
Ransomware
Known
Articles
0

Timeline

Published

Nov 7, 2023

Added to KEV

Nov 7, 2023

Remediation Due

Nov 28, 2023

Affected Product

Atlassian

Confluence Data Center and Server

View all Atlassian CVEs