S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 9, 2024

CVE-2023-22518 Scanner

CVE-2023-22518 scanner - Improper Authorization vulnerability in Atlassian Confluence Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2023-22518
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability.  Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Confluence Data Centerby Atlassian
< 1.0.0
Confluence Serverby Atlassian
< 1.0.0
Updated Aug 19, 2026View on NVD →
Detail

Atlassian Confluence Server is a widely used collaboration tool for teams to share knowledge efficiently. This platform enables users to create, collaborate, and organize all their work in one place. Confluence is utilized across various sectors, including technology, finance, and education, by small teams to large enterprises. Its flexibility and integration with Atlassian’s other tools like Jira make it a central component for project management and documentation. The vulnerability affects all versions of Confluence Data Center and Server, but Atlassian Cloud sites are not impacted.

The vulnerability in Atlassian Confluence Server involves improper authorization, which can lead to unauthorized actions on the server without proper authentication. This critical security issue allows attackers to bypass security measures and perform restricted operations. The flaw has a significant impact on the confidentiality, integrity, and availability of the system, making it a high-risk vulnerability. It is essential for users to address this vulnerability to protect their Confluence Server instances from potential exploitation.

This security flaw is present in the setup-restore functionality of the Atlassian Confluence Server. Attackers can exploit this vulnerability by sending a specially crafted HTTP request to the server. The request attempts to upload an invalid (empty) zip file through the 'setup-restore.action' endpoint. This method is intended to check for the vulnerability without causing data loss or database reset. In a real attack scenario, a malicious file could be used, causing more severe impacts.

Exploiting this vulnerability could allow attackers to gain unauthorized access to the Confluence Server, leading to data theft, unauthorized changes, or even full system compromise. This could result in the exposure of sensitive information, disruption of operations, and a significant impact on the organization’s reputation. Addressing this vulnerability is critical to prevent potential exploitation and safeguard the confidentiality, integrity, and availability of the Confluence Server.

By becoming a member of the S4E platform, you gain access to advanced scanning capabilities that help identify vulnerabilities like CVE-2023-22518 in your digital infrastructure. Our platform provides comprehensive cyber threat exposure management, helping you stay ahead of security risks. With real-time monitoring, actionable insights, and expert support, you can enhance your cybersecurity posture, protect your digital assets, and ensure business continuity. Join us today to benefit from our proactive security measures and safeguard your organization against emerging threats.

 

References

Solution Advice
  1. Immediately update to the latest version of Atlassian Confluence Server that addresses this vulnerability.
  2. Regularly check Atlassian’s official documentation and security advisories for updates and patches.
  3. Review and tighten access controls and authorization mechanisms on your Confluence Server.
  4. Monitor network traffic and logs for suspicious activities that may indicate attempts to exploit this vulnerability.
  5. Consider implementing additional security measures such as a web application firewall (WAF) to provide an extra layer of protection.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.