Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in
Celebration

Earn badges and make progress

You're on your way to the next level! Join the Kudos program to earn points and save your progress.

Deleted user Avatar
Deleted user

Level 1: Seed

25 / 150 points

Next: Root

Avatar

1 badge earned

Collect

Participate in fun challenges

Challenges come and go, but your rewards stay with you. Do more to earn more!

Challenges
Coins

Gift kudos to your peers

What goes around comes around! Share the love by gifting kudos to your peers.

Recognition
Ribbon

Rise up in the ranks

Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!

Leaderboard

How to confirm logs show no signs of exploitation for CVE-2023-22518

Edited

If a Confluence server is compromised the FAQ page shows examples of what to search for in the logs that could confirm it, but some of the items are not always matching up in regards to the keywords to use for search and what logs these show up in.

Is there a keyword to search for that if not found at all in any of the logs would confirm that it's not compromised?

1 answer

1 accepted

1 vote
Answer accepted
Dan Breyen
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
Nov 07, 2023

faq-for-cve-2023-22518-1311474094 

improper-authorization-vulnerability-in-confluence-data-center-and-server 

Hi @acast2 Based on those 2 articles I don't see anything like a keyword search to know if it's not compromised.  In my opinion, (for what it's worth) if it was my system, I would go through the mitigation process anyway.

Hope that helps.

After posting this, I received confirmation from Atlassian that if the keywords given within their documentation that you mentioned along with the FAQ then that means there is no attempt or confirmed exploit, so I went through logs from previous backups and confirmed that they were not compromised, so I got my answer.

As you said, I too agree about going through the mitigation process which is what I'm currently doing...thanks

Like Laurie Sciutti likes this

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
TAGS
AUG Leaders

Atlassian Community Events