Author: vulnmachines - Bewertung: 24x - Views:1174
On October 4, 2023, Atlassian released an advisory for CVE-2023-22515, a critical vulnerability affecting on-premises instances of Confluence Server and Confluence Data Center. Atlassian initially described this vulnerability as a Privilege Escalation, but they have since recategorized it as a Broken Access Control vulnerability. Atlassian has provided a CVSS base score of 10.0, which appears appropriate based on our analysis.
Atlassian indicated that this vulnerability was exploited in the wild as a zero-day vulnerability, prior to their knowledge or a patch being available. The observed attacker behavior included leveraging CVE-2023-22515 to create a new administrator user, but we believe that this is not the only way the vulnerability could be used.
Vulnmachines - Place for Pentesters
Vulnmachines is online cyber security training platform with a massive number of labs, allowing individuals, students, cyber professionals, companies, universities and all kinds of organizations around the world to enhance their practical skills with Real-world enterprise scenarios.
Visit : https://www.vulnmachines.com
TheSecOps Group : The SecOps Group is founded by industry veterans. We have over 15 years of experience in providing cyber security consultancy and have worked with some of the largest blue chip companies. Being an independent boutique company, we enable our customers to continuously identify and assess their security postures and provide advice in securing against the adversaries.
Our team regularly speaks at international conferences (including Black Hat, Defcon, HITB, and OWASP Appsec). We pride ourselves in hiring the best talent and our passion is to stay up-to-date with the latest in the world of ethical hacking.
For business: https://secops.group/
Follow us
Twitter : https://www.twitter.com/vulnmachines
Facebook : https://www.fb.com/vulnmachines
LinkedIn : https://www.linkedin.com/company/vulnmachines
#bugbounty #bugbountytips #confluence #cve #infosec #cybersecurity #ethicalhacking #learning #cyber