The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

🚨Patch your Confluence Server/DC instances! (CVE-2023-22518)

This bears repeating: please patch your Confluence instances ASAP.

If you are using Confluence Server or Confluence Data Center, update to a fixed version as soon as you can.

👉 See Atlassian's security bulletin for the list of patched versions: https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html

Naturally there are many Confluence admins in the Enterprise group, so this warranted an alert. Atlassian may have already reached out to you directly if you're a technical contact for an active Confluence license.

5 comments

Comments for this post are closed

Community moderators have prevented the ability to post new comments.

Dave LIAO
Community Champion
November 8, 2023

📌 I will un-pin this article from the Enterprise group on the 20th.

Bill Bailey
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
November 8, 2023

Would have been nice to have been alerted to this issue before telling the hacker community. Every license has associated technical contacts who could have been contacted before going public.

Like # people like this
Dave LIAO
Community Champion
November 8, 2023

@Bill Bailey - agreed.

Like Andy Gladstone likes this
David Yu
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
November 8, 2023

For the longest time, we've been asking for authentication on all public endpoints if it's operating in private mode. https://jira.atlassian.com/browse/JRASERVER-65521

I guess it's a hard problem to solve; but it would have reduced the severity of a whole class of CVEs.

Like Dave LIAO likes this
hbunjes
Contributor
November 8, 2023

We’ve been attacked starting October 26th. The patch was too late for us unfortunately. I don’t think anyone still has a working confluence instance if it’s not patched. 

I got a mail on Oct 31st from Atlassian regarding this security issue. So, I think Atlassian has informed the customers on time as soon as they could. However, I don’t get the statement „There are no reports of active exploitation at this time“ as there were obviously a lot of attacks at this time for various customers. 

Comments for this post are closed

Community moderators have prevented the ability to post new comments.

TAGS
AUG Leaders

Atlassian Community Events