S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2023-22527 Scanner

CVE-2023-22527 Scanner - Remote Code Execution (RCE) vulnerability in Atlassian Confluence

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.3k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2023-22527
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Confluence Data Centerby Atlassian
< 8.0.0
Confluence Serverby Atlassian
< 8.0.0
confluence_data_centerby atlassian
AFFECTED< 8.5.4SAFE ✓≥ 8.5.4
confluence_serverby atlassian
AFFECTED< 8.5.4SAFE ✓≥ 8.5.4
Updated Aug 19, 2026View on NVD →
Detail

Atlassian Confluence is a popular collaboration software tool used by organizations to create, share, and organize content for team projects. Confluence is widely deployed in both Data Center and Server environments, particularly in sectors requiring robust documentation and information sharing across teams. The software is commonly utilized by project managers, software engineers, and administrators to streamline workflows and enhance productivity within an organization. Organizations often rely on Confluence to manage various aspects of project development, communication, and data organization. The application’s extensive feature set allows for customized use cases suited to specific business requirements. Confluence is a valuable resource for collaborative content management and seamless information dissemination in various professional settings.

This vulnerability, a Remote Code Execution (RCE), arises due to a Server-Side Template Injection (SSTI) flaw in older versions of Confluence Data Center and Server. Exploitation of this vulnerability enables an unauthenticated attacker to inject arbitrary code through crafted requests, bypassing regular access restrictions. SSTI vulnerabilities like this allow threat actors to execute unauthorized commands by exploiting input fields that process templates unsafely. This vulnerability can lead to significant security risks in affected systems, as it bypasses standard security protocols. Attackers leveraging this RCE flaw may execute arbitrary system commands, compromise data integrity, and potentially control the system remotely. Immediate patching or mitigation is advised to prevent exploitation.

In this SSTI-based Remote Code Execution vulnerability, an attacker sends specially crafted requests that target an unprotected endpoint within Confluence, specifically the "template/aui/text-inline.vm" endpoint. Through this request, attackers can manipulate OGNL expressions within the Confluence environment, exploiting an internal Freemarker template to run arbitrary commands. The vulnerability stems from inadequate input sanitization in Confluence’s template rendering process, allowing injection payloads. Attackers use this endpoint to perform arbitrary operations by invoking objects in the backend code, which would not be possible with standard access controls.

When exploited, this vulnerability enables attackers to gain unauthorized access to the affected system, execute arbitrary system commands, and potentially achieve persistent access. This can lead to critical security risks, such as data exfiltration, malware deployment, or further infiltration into the organization's internal systems. Additionally, the vulnerability could allow attackers to leverage Confluence as a launch point for broader attacks against connected systems.

REFERENCES

Solution Advice
  • Update to the latest version of Atlassian Confluence to apply security patches.
  • Limit network exposure for Confluence to only trusted networks if possible.
  • Implement network-level monitoring for unusual activity on Confluence instances.
  • Consider isolating Confluence instances from sensitive internal resources.
  • Regularly review and adjust permissions for user accounts with access to Confluence.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.