Atlassian Bug Escalated to 10, All Unpatched Instances Vulnerable
Active ransomware attacks against vulnerable Atlassian Confluence Data Center and Servers ratchets up risk to enterprises, now reflected in the bug's revised CVSS score of 10.
November 7, 2023
Active ransomware and other cyberattacks against unpatched Atlassian Confluence Data Center and Server technology have driven up the CVSS score of the related vulnerability from its original 9.1 to 10, the most critical rating on the scale.
All versions of Atlassian Confluence Data Center and Server are impacted, according to Atlassian, though cloud instances are not.
The improper authorization flaw's score, tracked under CVE-2023-22518, has been raised "due to a change in scope of the attack," according to the Atlassian advisory, which added there have now been observed active exploits against against the bug, including ransomware. Researchers at Rapid7 also issued an advisory warning of snowballing attacks starting over the weekend.
Atlassian, an Australian company, develops tools for software development and collaboration.
"This improper authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account," the advisory added. "Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to a full loss of confidentiality, integrity and availability."
First disclosed on Oct. 31, the Atlassian Confluence vulnerability was observed under active exploit by Nov. 3.
Right now, Atlassian said it can't confirm which customer instances have been impacted by the active attacks, but the company warns security teams to look for the following:
loss of login or access
requests to /json/setup-restore* in network access logs
installed unknown plugins, with observed reports of a plugin named "web.shell.Plugin"
encrypted files or corrupted data
unexpected members of the confluence-administrators group
unexpected newly created user accounts
About the Author
You May Also Like
How to Evaluate Hybrid-Cloud Network Policies and Enhance Security
September 18, 2024DORA and PCI DSS 4.0: Scale Your Mainframe Security Strategy Among Evolving Regulations
September 26, 2024Harnessing the Power of Automation to Boost Enterprise Cybersecurity
October 3, 202410 Emerging Vulnerabilities Every Enterprise Should Know
October 30, 2024
State of AI in Cybersecurity: Beyond the Hype
October 30, 2024[Virtual Event] The Essential Guide to Cloud Management
October 17, 2024Black Hat Europe - December 9-12 - Learn More
December 10, 2024SecTor - Canada's IT Security Conference Oct 22-24 - Learn More
October 22, 2024