Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Feb 14, 2024

High
CISA KEVRansomware

CVE-2023-22527

AtlassianConfluence Data Center and Server

Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.

Required Action

https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html; https://nvd.nist.gov/vuln/detail/CVE-2023-22527

Vulnerability Overview

Severity
High
CISA KEV
Yes
Ransomware
Known
Published
Jan 24, 2024
KEV Added
Jan 24, 2024
Due Date
Feb 14, 2024
Related Articles
0

Vendor

Atlassian

Confluence Data Center and Server