[High Risk] Atlassian Confluence Remote Code Execution Vulnerability

 Vulnerability description

 Confluence is a knowledge management and collaboration software developed by Atlassian, and is usually used as a wiki system within enterprises.

Confluence 7.19.8 to versions earlier than 8.2.0 have a remote code execution vulnerability, an attacker with login privileges can execute arbitrary commands in the Confluence server without user interaction.

Vulnerability name Atlassian Confluence Remote Code Execution Vulnerability
Vulnerability type code injection
Discovery time 2023/7/19
Vulnerability Breadth generally
MPS number MPS-2023-0009
CVE number CVE-2023-22508
CNVD number -


Sphere of influence

Confluence@[7.19.8, 8.2.0)

Repair plan

Upgrade Confluence to 8.2.0 or later

The official patch has been released: https://www.atlassian.com/software/confluence/download-archives

reference link

https://www.oscs1024.com/hd/MPS-2023-0009

https://nvd.nist.gov/vuln/detail/CVE-2023-22508

https://jira.atlassian.com/browse/CONFSERVER-88221

https://www.atlassian.com/software/confluence/download-archives

About Murphy Security 

Murphy Security is a technology company that provides you with professional software supply chain security management. The core team comes from Baidu, Huawei, Wuyun and other enterprises. The company provides customers with a complete software supply chain security management platform, and provides software with a full life cycle around SBOM Security management, platform capabilities include software component analysis, source security management, container image detection, vulnerability intelligence early warning and commercial software supply chain access assessment and other products. Provide customers with complete control capabilities from supply chain asset identification management, risk detection, security control, and one-key repair.

Open source project: https://github.com/murphysecurity/murphysec/?sf=qbyj

The product can be integrated with various tools in the existing development process at a very low cost, including seamless integration with dozens of tools such as IDE, Gitlab, Bitbucket, Jenkins, Harbor, and Nexus.

Free code security detection tool:  https://www.murphysec.com/?sf=qbyj
Free intelligence subscription: https://www.oscs1024.com/cm/?sf=qbyj


Guess you like

Origin blog.csdn.net/murphysec/article/details/131923741