CVE-2023-22518

unknown KEV
Published 2023-11-07 · Modified 2023-11-07
CVSS v3
CVSS v2
VIR risk
1.5

Description

Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.

CISA KEV

Vendor
Atlassian
Product
Confluence Data Center and Server
Due date
2023-11-28

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html; https://nvd.nist.gov/vuln/detail/CVE-2023-22518

Exploits

References

Verify integrity in audit chain (admin only). AS-IS.