This bears repeating: please patch your Confluence instances ASAP.
If you are using Confluence Server or Confluence Data Center, update to a fixed version as soon as you can.
👉 See Atlassian's security bulletin for the list of patched versions: https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html
Naturally there are many Confluence admins in the Enterprise group, so this warranted an alert. Atlassian may have already reached out to you directly if you're a technical contact for an active Confluence license.
📌 I will un-pin this article from the Enterprise group on the 20th.
Would have been nice to have been alerted to this issue before telling the hacker community. Every license has associated technical contacts who could have been contacted before going public.
@Bill Bailey - agreed.
For the longest time, we've been asking for authentication on all public endpoints if it's operating in private mode. https://jira.atlassian.com/browse/JRASERVER-65521
I guess it's a hard problem to solve; but it would have reduced the severity of a whole class of CVEs.
We’ve been attacked starting October 26th. The patch was too late for us unfortunately. I don’t think anyone still has a working confluence instance if it’s not patched.Â
I got a mail on Oct 31st from Atlassian regarding this security issue. So, I think Atlassian has informed the customers on time as soon as they could. However, I don’t get the statement „There are no reports of active exploitation at this time“ as there were obviously a lot of attacks at this time for various customers.Â
It looks like you're new here. Sign in or register to get started.