Template injection in Confluence Data Center and Confluence Server - CVE-2023-22527
Published: January 16, 2024 / Updated: February 25, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation. A remote attacker can send a specially crafted request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Confluence Server
How to mitigate CVE-2023-22527
Confluence Server - update to 8.5.4
Links to Public Exploits and PoC-codes
- Exploit #11169 - CVE-2023-22527 (An Exploitation tool to exploit the confluence server that are vulnerable to CVE-2023-22527 leads to RCE) (February 25, 2025)
- Exploit #10717 - Atlassian Confluence < 8.5.3 - Remote Code Execution (October 25, 2024)
- Exploit #10574 - CVE-2023-22527 (script for exploiting CVE-2023-22527, which is described as a Server-Side Template Injection (SSTI) vulnerability in Atlassian Confluence) (October 11, 2024)
- Exploit #10138 - CVE-2023-22527-confluence ([Confluence] CVE-2023-22527 realworld poc) (June 28, 2024)
- Exploit #9788 - CVE-2023-22527-POC (A critical severity Remote Code Execution (RCE) vulnerability (CVE-2023-22527) was discovered in Confluence Server and Data Center. ) (May 13, 2024)
- Exploit #9686 - CVE-2023-22527 (CVE-2023-22527 - RCE (Remote Code Execution) Vulnerability In Confluence Data Center and Confluence Server PoC) (April 5, 2024)
- Exploit #9617 - CVE-2023-22527 (This repository presents a proof-of-concept of CVE-2023-22527) (March 22, 2024)
- Exploit #9614 - CVE-2023-22527-MEMSHELL (confluence CVE-2023-22527 漏洞利用工具,支持冰蝎/哥斯拉内存马注入,支持设置 http 代理) (March 22, 2024)
- Exploit #9597 - CVE-2023-22527-Godzilla-MEMSHELL (CVE-2023-22527 内存马注入工具) (March 4, 2024)
- Exploit #9584 - CVE-2023-22527_Confluence_RCE (CVE-2023-22527 - RCE (Remote Code Execution) Vulnerability In Confluence Data Center and Confluence Server PoC) (March 4, 2024)
- Exploit #9527 - CVE-2023-22527 (Exploit for CVE-2023-22527 - Atlassian Confluence Data Center and Server) (January 26, 2024)
- Exploit #9523 - Atlassian Confluence SSTI Injection (January 25, 2024)
- Exploit #9518 - CVE-2023-22527 (An Exploitation tool to exploit the confluence server that are vulnerable to CVE-2023-22527 leads to RCE) (January 23, 2024)