CVE-2023-22518
Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 9.8
- EPSS
- 100.0% 백분위 100.0% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2023.11.28
- 공개일
- 2023.11.01
CISA KEV에 등록된 실제 악용 확인 취약점
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net dom...
공급사 Atlassian
제품 Confluence Data Center and Server
영향 버전 >= 1.0.0, >= 1.0 < 7.19.16, >= 7.20.0 < 8.3.4, >= 8.4.0 < 8.4.4, >= 8.5.0 < 8.5.3, 8.6.0
수정 버전 7.19.16, 8.3.4, 8.4.4, 8.5.3
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
조치 기한: 2023.11.28CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE CWE-863
KEV 등록일 2023.11.07
랜섬웨어 캠페인 사용 확인됨
CISA 비고 https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html; https://nvd.nist.gov/vuln/detail/CVE-2023-22518
EPSS 데이터 기준일 2026.06.27