CVE-2023-22515

CRITICAL KEV RANSOMWARE NUCLEI

Atlassian Confluence Unauthenticated Remote Code Execution

Title source: metasploit

Description

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

Exploits (36)

nomisec WORKING POC 148 stars
by Chocapikk · remote
https://github.com/Chocapikk/CVE-2023-22515
nomisec WORKING POC 110 stars
by ad-calcium · remote
https://github.com/ad-calcium/CVE-2023-22515
nomisec SCANNER 78 stars
by ErikWynter · poc
https://github.com/ErikWynter/CVE-2023-22515-Scan
nomisec WORKING POC 52 stars
by AIex-3 · remote
https://github.com/AIex-3/confluence-hack
nomisec WORKING POC 25 stars
by K4ptor · poc
https://github.com/K4ptor/CVE-2023-22515
nomisec WORKING POC 23 stars
by aaaademo · poc
https://github.com/aaaademo/Confluence-EvilJar
nomisec WRITEUP 20 stars
by youcannotseemeagain · poc
https://github.com/youcannotseemeagain/CVE-2023-22515_RCE
nomisec WORKING POC 8 stars
by j3seer · remote
https://github.com/j3seer/CVE-2023-22515-POC
nomisec WORKING POC 6 stars
by Le1a · remote
https://github.com/Le1a/CVE-2023-22515
nomisec WORKING POC 4 stars
by kh4sh3i · remote
https://github.com/kh4sh3i/CVE-2023-22515
nomisec WORKING POC 4 stars
by spareack · remote
https://github.com/spareack/CVE-2023-22515-NSE
nomisec STUB 3 stars
by Vulnmachines · remote
https://github.com/Vulnmachines/confluence-cve-2023-22515
nomisec WRITEUP 2 stars
by LucasPDiniz · remote
https://github.com/LucasPDiniz/CVE-2023-22515
nomisec SCANNER 2 stars
by fyx1t · infoleak
https://github.com/fyx1t/NSE--CVE-2023-22515
nomisec WRITEUP 1 stars
by Arkha-Corvus · poc
https://github.com/Arkha-Corvus/LetsDefend-SOC235-Atlassian-Confluence-Broken-Access-Control-0-Day-CVE-2023-22515-EventID-197
nomisec SCANNER 1 stars
by rxerium · infoleak
https://github.com/rxerium/CVE-2023-22515
nomisec WORKING POC 1 stars
by C1ph3rX13 · remote
https://github.com/C1ph3rX13/CVE-2023-22515
nomisec WORKING POC 1 stars
by iveresk · poc
https://github.com/iveresk/CVE-2023-22515
nomisec WRITEUP
by dkq-k · remote
https://github.com/dkq-k/cve-2023-22515-1
nomisec WRITEUP
by dkq-k · remote
https://github.com/dkq-k/CVE-2023-22515
nomisec SUSPICIOUS
by Onedy1703 · remote
https://github.com/Onedy1703/CVE-2023-22515-Confluence
nomisec STUB
by CyberSentinel321 · poc
https://github.com/CyberSentinel321/cve-2023-22515-lab
nomisec WRITEUP
by tranphuc2005 · remote
https://github.com/tranphuc2005/CVE-2023-22515
nomisec WORKING POC
by vivigotnotime · remote
https://github.com/vivigotnotime/CVE-2023-22515-Exploit-Script
nomisec SCANNER
by s1d6point7bugcrowd · poc
https://github.com/s1d6point7bugcrowd/CVE-2023-22515-check
nomisec WORKING POC
by xorbbo · remote
https://github.com/xorbbo/cve-2023-22515
nomisec SCANNER
by edsonjt81 · poc
https://github.com/edsonjt81/CVE-2023-22515-Scan.
nomisec WORKING POC
by CalegariMindSec · remote
https://github.com/CalegariMindSec/Exploit-CVE-2023-22515
nomisec WORKING POC
by INTfinityConsulting · remote
https://github.com/INTfinityConsulting/cve-2023-22515
nomisec WORKING POC
by killvxk · poc
https://github.com/killvxk/CVE-2023-22515-joaoviictorti
nomisec WORKING POC
by DsaHen · remote
https://github.com/DsaHen/cve-2023-22515-exp
vulncheck_xdb WORKING POC
remote
https://github.com/sincere9/CVE-2023-22515
metasploit WORKING POC
by Unknown, Emir Polat · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/atlassian_confluence_auth_bypass.rb
metasploit WORKING POC EXCELLENT
by sfewer-r7 · rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/atlassian_confluence_rce_cve_2023_22515.rb

Nuclei Templates (1)

Atlassian Confluence - Privilege Escalation
CRITICALVERIFIEDby s1r1us,iamnoooob,rootxharsh,pdresearch
Shodan: http.component:"atlassian confluence"
FOFA: app="ATLASSIAN-Confluence" || app="atlassian-confluence"

Scores

CVSS v3 9.8
EPSS 0.9433
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2023-10-05
VulnCheck KEV 2023-10-04
InTheWild.io 2023-10-04
ENISA EUVD EUVD-2023-26655
Ransomware Use Confirmed
CWE
CWE-20
Status published
Products (46)
Atlassian/Confluence Data Center < 8.0.0
Atlassian/Confluence Data Center >= 8.0.0
Atlassian/Confluence Data Center >= 8.0.1
Atlassian/Confluence Data Center >= 8.0.2
Atlassian/Confluence Data Center >= 8.0.3
Atlassian/Confluence Data Center >= 8.1.3
Atlassian/Confluence Data Center >= 8.1.4
Atlassian/Confluence Data Center >= 8.2.0
Atlassian/Confluence Data Center >= 8.2.1
Atlassian/Confluence Data Center >= 8.2.2
... and 36 more
Published Oct 04, 2023
KEV Added Oct 05, 2023
Tracked Since Feb 18, 2026