CVE-2023-22527

CRITICAL KEV RANSOMWARE NUCLEI

Atlassian Confluence SSTI Injection

Title source: metasploit

Description

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.

Exploits (27)

nomisec WORKING POC 76 stars
by Boogipop · remote
https://github.com/Boogipop/CVE-2023-22527-Godzilla-MEMSHELL
nomisec WORKING POC 41 stars
by M0untainShley · remote
https://github.com/M0untainShley/CVE-2023-22527-MEMSHELL
nomisec WORKING POC 25 stars
by Avento · poc
https://github.com/Avento/CVE-2023-22527_Confluence_RCE
nomisec WORKING POC 22 stars
by Manh130902 · remote
https://github.com/Manh130902/CVE-2023-22527-POC
nomisec WORKING POC 19 stars
by VNCERT-CC · remote
https://github.com/VNCERT-CC/CVE-2023-22527-confluence
nomisec WORKING POC 12 stars
by Vozec · remote
https://github.com/Vozec/CVE-2023-22527
nomisec WORKING POC 9 stars
by RevoltSecurities · remote
https://github.com/RevoltSecurities/CVE-2023-22527
nomisec WORKING POC 9 stars
by Chocapikk · remote
https://github.com/Chocapikk/CVE-2023-22527
nomisec WORKING POC 6 stars
by vulncheck-oss · remote
https://github.com/vulncheck-oss/cve-2023-22527
nomisec WORKING POC 5 stars
by BBD-YZZ · remote
https://github.com/BBD-YZZ/Confluence-RCE
nomisec WORKING POC 5 stars
by adminlove520 · remote
https://github.com/adminlove520/CVE-2023-22527
nomisec WORKING POC 5 stars
by Privia-Security · remote
https://github.com/Privia-Security/CVE-2023-22527
nomisec WORKING POC 5 stars
by thanhlam-attt · remote
https://github.com/thanhlam-attt/CVE-2023-22527
nomisec WORKING POC 4 stars
by yoryio · remote
https://github.com/yoryio/CVE-2023-22527
nomisec WORKING POC 4 stars
by C1ph3rX13 · remote
https://github.com/C1ph3rX13/CVE-2023-22527
nomisec NO CODE 3 stars
by Sudistark · poc
https://github.com/Sudistark/patch-diff-CVE-2023-22527
nomisec WORKING POC 2 stars
by Niuwoo · remote
https://github.com/Niuwoo/CVE-2023-22527
nomisec STUB 2 stars
by Drun1baby · remote
https://github.com/Drun1baby/CVE-2023-22527
nomisec WORKING POC 1 stars
by MaanVader · remote
https://github.com/MaanVader/CVE-2023-22527-POC
nomisec WORKING POC 1 stars
by kh4sh3i · remote
https://github.com/kh4sh3i/CVE-2023-22527
nomisec WRITEUP 1 stars
by ga0we1 · poc
https://github.com/ga0we1/CVE-2023-22527_Confluence_RCE
nomisec WORKING POC 1 stars
by mylo-2001 · poc
https://github.com/mylo-2001/AtlassianPwn
nomisec WORKING POC
by thompson005 · poc
https://github.com/thompson005/CVE-2023-22527
nomisec WORKING POC
by YongYe-Security · remote
https://github.com/YongYe-Security/CVE-2023-22527
metasploit WORKING POC EXCELLENT
by Rahul Maini, Harsh Jaiswal, Spencer McIntyre · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/atlassian_confluence_rce_cve_2023_22527.rb

Nuclei Templates (1)

Atlassian Confluence - Remote Code Execution
CRITICALby iamnooob,rootxharsh,pdresearch
Shodan: http.component:"Atlassian Confluence" || http.component:"atlassian confluence"
FOFA: app="atlassian-confluence"

Scores

CVSS v3 9.8
EPSS 0.9436
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2024-01-24
VulnCheck KEV 2024-01-19
InTheWild.io 2024-01-23
ENISA EUVD EUVD-2023-26667
Ransomware Use Confirmed

Classification

CWE
CWE-74
Status published

Affected Products (3)

atlassian/confluence_data_center < 8.5.4
atlassian/confluence_data_center
atlassian/confluence_server < 8.5.4

Timeline

Published Jan 16, 2024
KEV Added Jan 24, 2024
Tracked Since Feb 18, 2026