Rapid7 mentions in their blog post that they exploited the vulnerability CVE-2023-22515 with the endpoint /server-info.action which isn't mentioned in the advisory. Also if it is the case, that this endpoint allows also the creation of an admin account, the workaround won't work.
Can Atlassian confirm this and update the advisory with the additional IoC?