Improper Authentication in Confluence Data Center - CVE-2023-22515
Published: October 5, 2023 / Updated: February 25, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to missing authentication at the "/setup/setupadministrator.action" endpoint. A remote non-authenticated attacker can send specially crafted requests to the server to create an administrative account and gain unauthorized access to the system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2023-22515
Links to Public Exploits and PoC-codes
- Exploit #11177 - CVE-2023-22515-Exploit-Script () (February 25, 2025)
- Exploit #11099 - CVE-2023-22515 (Confluence Data Center & Server 权限提升漏洞 Exploit) (January 31, 2025)
- Exploit #10882 - NSE--CVE-2023-22515 (NSE script for checking the presence of CVE-2023-22515) (November 22, 2024)
- Exploit #10716 - Atlassian Confluence Data Center and Server - Authentication Bypass (Metasploit) (October 25, 2024)
- Exploit #10451 - CVE-2023-22515 (Confluence未授权添加管理员用户漏洞利用脚本) (August 30, 2024)
- Exploit #10254 - CVE-2023-22515 (CVE 2023-22515) (July 26, 2024)
- Exploit #9925 - CVE-2023-22515-check (This script will inform the user if the Confluence instance is vulnerable, but it will not proceed with the exploitation steps.) (June 7, 2024)
- Exploit #9683 - CVE-2023-22515 (Confluence未授权添加管理员用户(CVE-2023-22515)漏洞利用工具) (April 5, 2024)
- Exploit #9628 - CVE-2023-22515-Scan (Scanner for CVE-2023-22515 - Broken Access Control Vulnerability in Atlassian Confluence) (March 22, 2024)
- Exploit #9501 - confluence-hack (CVE-2023-22515) (January 15, 2024)
- Exploit #9384 - Atlassian Confluence Data Center and Server Authentication Bypass via Broken Access Control (October 20, 2023)
- Exploit #9383 - Atlassian Confluence Unauthenticated Remote Code Execution (October 19, 2023)
- Exploit #9376 - CVE-2023-22515 (CVE-2023-22515 - Broken Access Control Vulnerability in Confluence Data Center and Server) (October 11, 2023)
External References
- https://jira.atlassian.com/browse/CONFSERVER-92457
- https://confluence.atlassian.com/display/KB/FAQ+for+CVE-2023-22515
- https://confluence.atlassian.com/pages/viewpage.action?pageId=1295682276
- https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html