• News/
  • https://www.bleepingcomputer.com/news/security/atlassian-warns-of-critical-rce-flaw-in-older-confluence-versions/

Atlassian warns of critical RCE flaw in older Confluence versions

BleepingComputer
·
Bill Toulas
·
Published Jan 16, 2024
·
Updated

Atlassian Confluence Data Center and Confluence Server are vulnerable to a critical remote code execution (RCE) vulnerability that impacts versions released before December 5, 2023, including out-of-support releases. The flaw is tracked as CVE-2023-22527, rated critical (CVSS v3: 10.0), and is a template injection vulnerability allowing unauthenticated attackers to perform remote code execution on impacted Confluence endpoints. "Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular updates," reads Atlassian's security bulletin. "However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian's January Security Bulletin." The RCE bug impacts Confluence Data Center and Server versions 8.0.x, 8.1.x, 8.2.x, 8.3.x, 8.4.x, and 8.5.0 through 8.5.3. Atlassian fixed the flaw in Confluence Data Center and Server versions 8.5.4 (LTS), 8.6.0 (Data Center only), and 8.7.1 (Data Center only), which were released in December. However, it is unclear if they quietly fixed the bug last month or if it was inadvertently fixed during their regular software development. These versions were released earlier and aren't the latest anymore, so admins who have moved to a more recent release are safe from CVE-2023-22527 exploitation. Atlassian notes that 8.4.5 and all previous release branches that have...

Read full article

Affected Software

21 affected components
Atlassian Confluence Data Center=8.0.x
Atlassian Confluence Data Center=8.1.x
Atlassian Confluence Data Center=8.2.x
Atlassian Confluence Data Center=8.3.x
Atlassian Confluence Data Center=8.4.x
Atlassian Confluence Data Center=8.5.0
Atlassian Confluence Data Center=8.5.1
Atlassian Confluence Data Center=8.5.2
Atlassian Confluence Data Center=8.5.3
Atlassian Confluence Server=8.0.x
Atlassian Confluence Server=8.1.x
Atlassian Confluence Server=8.2.x
Atlassian Confluence Server=8.3.x
Atlassian Confluence Server=8.4.x
Atlassian Confluence Server=8.5.0
Atlassian Confluence Server=8.5.1
Atlassian Confluence Server=8.5.2
Atlassian Confluence Server=8.5.3
Atlassian Confluence Server=8.5.4 (LTS)
Atlassian Confluence Server=8.6.0 (Data Center only)
Atlassian Confluence Server=8.7.1 (Data Center only)

Frequently Asked Questions

1

What is the critical vulnerability discussed in the article?

The article discusses a critical remote code execution (RCE) vulnerability affecting older versions of Atlassian Confluence.

2

Which versions of Atlassian Confluence are impacted by the RCE flaw?

The vulnerability affects Confluence Server and Data Center versions released before December 5, 2023, specifically versions 8.0.x to 8.7.1.

3

What actions should users of affected Confluence versions take?

Users of affected versions should update their Confluence software to the latest release to mitigate the vulnerability.

4

How severe is the security risk associated with the RCE vulnerability?

The RCE vulnerability is classified as critical, posing significant risks to user systems if exploited.

5

Are both Confluence Server and Confluence Data Center impacted by the flaw?

Yes, both Confluence Server and Confluence Data Center are affected by the critical RCE vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203