No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Critical Atlassian Bug Exploit Now Available; Immediate Patching Needed

November 4, 2023
in Protection
0
informa



Proof of concept (PoC) exploit code for a critical vulnerability that Atlassian disclosed in its Confluence Data Center and Server technology has become publicly available, heightening the need for organizations using the collaboration platform to immediately apply the company’s fix for it.

ShadowServer, which monitors the Internet for malicious activity, on Nov. 3 reported that it observed attempts to exploit the Atlassian vulnerability from at least 36 unique IP addresses over the last 24 hours.

Atlassian disclosed the near maximum severity bug (9.1 out of 10 on the CVSS scale) on Oct. 31 with a warning from its CISO about the vulnerability presenting a risk of “significant data loss” if exploited.

Vulnerability Information Publicly Available

The bug, assigned the identifier CVE-2023-22518, affects customers of all versions of Atlassian Data Center and Atlassian Server but not those using the company’s cloud hosted versions of these technologies. Atlassian’s description of the bug identified it as an issue that involves low attack complexity, no user interaction and something that an attacker would be able to exploit with little to no special privileges.

The vulnerability has to do with improper authorization, which basically is a weakness that allows an attacker to gain access to privileged functionality and data in an application. In this case, an attacker who exploits the vulnerability would be able to delete data on a Confluence instance or block access to it. But they would not be able to exfiltrate data from it, according to an analysis by security intelligence firm Field Effect.

On Nov. 2, Atlassian updated its vulnerability alert from Oct. 31 with a warning about technical details of CVE-2023-22518 becoming publicly available. The information increases the risk of attackers exploiting the vulnerability, Atlassian said. “There are still no reports of an active exploit, though customers must take immediate action to protect their instances,” the company said. The advice echoed Atlassian’s recommendation when it first disclosed the bug earlier this week. The company has recommended that organizations which cannot immediately patch should remove their Confluence instances from the Internet until they can patch.

Large Number of Exposed Systems

ShadowServer described the increasing exploit activity as involving attempts to upload files and set up or to restore vulnerable Internet accessible Confluence instances.

“We see around 24K exposed (not necessarily vulnerable),” Atlassian Confluence instances ShadowServer said. A plurality of the exposed systems — some 5,500 — are located in the United States. Other countries with a relatively high number of exposed Atlassian Confluence systems include China with some 3,000 systems, German with 2,000, and Japan with around 1,400 exposed instances.

CVE-2023-22518 is the second major vulnerability that Atlassian has disclosed in its widely used Confluence Data Center and Confluence Server collaboration technologies over the past month. On October 4, the company disclosed CVE-2023-22515, a maximum severity, broken access control bug. Atlassian only discovered the bug after some customers with public facing Confluence Data Center and Server instances reported encountering problems with it. Atlassian later identified the attacker as a nation-state actor.

As with the new bug, CVE-2023-22515 also involved low attack complexity. Worries of the ease with which it could be exploited prompted a joint advisory from the US Cybersecurity and Infrastructure Agency, the FBI, and the Multi-State Information Sharing and Analysis Center (MS-ISAC). The advisory warned organizations to be prepared for widespread exploit activity and urged them to patch the flaw as soon as possible.



Editorial Team

Editorial Team

Related Posts

This Sonos Soundbar With Alexa Is 46% Off Right Now
Protection

This Sonos Soundbar With Alexa Is 46% Off Right Now

April 17, 2026
What You Can Expect to Pay to Get Into Fitness
Protection

What You Can Expect to Pay to Get Into Fitness

April 17, 2026
This Tech Announcement From Bigme Was so Bad, the Company Apologized
Protection

This Tech Announcement From Bigme Was so Bad, the Company Apologized

April 17, 2026
This Arlo 2K Indoor/Outdoor Security Camera Is on Sale for $25
Protection

This Arlo 2K Indoor/Outdoor Security Camera Is on Sale for $25

April 17, 2026
You Can Get Windows 11 Pro on Sale for Just $13 Right Now
Protection

You Can Get Windows 11 Pro on Sale for Just $13 Right Now

April 17, 2026
This Flash Sale Offers a One-Year BJ's Membership With Gas Discounts for Just $15 Right Now
Protection

This Flash Sale Offers a One-Year BJ’s Membership With Gas Discounts for Just $15 Right Now

April 17, 2026
Load More
Next Post
Condé Nast Traveler

12 Best Travel Blankets for Long Flights and Road Trips (2023)

Popular News

  • Columbia Coupon Codes and Deals: 15% Off Jackets, Gear, and More

    Columbia Coupon Codes and Deals: 15% Off Jackets, Gear, and More

    0 shares
    Share 0 Tweet 0
  • My Path to Generational Wealth: ‘The Happy Investor Method’

    0 shares
    Share 0 Tweet 0
  • Russia launches lunar lander in race to find water on moon By Reuters

    0 shares
    Share 0 Tweet 0
  • 31 Best Jobs For Introverts In 2024: The Complete Guide

    0 shares
    Share 0 Tweet 0
  • 5 Things to Know About the Seen Mastercard

    0 shares
    Share 0 Tweet 0

Latest News

US Senator Blumenthal Presses Officials for Update on Binance Oversight

US Senator Blumenthal Presses Officials for Update on Binance Oversight

April 17, 2026
0

Connecticut Senator Richard Blumenthal questioned US authorities responsible for overseeing Binance about whether the company is complying with anti-money laundering...

Average tax refund is 11.2% higher, latest IRS filing data shows

Average tax refund is 11.2% higher, latest IRS filing data shows

April 17, 2026
0

Milan Markovic | E+ | Getty ImagesThe average tax refund is 11.2% higher this season, compared with about the same period in...

This Sonos Soundbar With Alexa Is 46% Off Right Now

This Sonos Soundbar With Alexa Is 46% Off Right Now

April 17, 2026
0

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of...

Bitcoin futures veteran Amir Zaidi returns to CFTC as chief of staff

Bitcoin Price Prediction: BTC Stalls Below $76K

April 17, 2026
0

Bitcoin price prediction turns cautious as BTC failed to sustain its third breakout attempt above $76,000, repeatedly touching the level...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.