Follow

We are seeing Atlassian Confluence CVE-2023-22527 pre-auth template injection RCE attempts since 2024-01-19.

Over 600 IPs seen attacking so far (testing callback attempts and 'whoami' execution).

Vulnerability affects out of date versions of Confluence: confluence.atlassian.com/secur

If you have exposed Atlassian Confluence instances make sure they are up to date (and if not check for signs of compromise!)

11,1K accessible: dashboard.shadowserver.org/sta

Info on exposed Atlassian Confluence instances in our Device Identification report: shadowserver.org/what-we-do/ne

· · Web · 1  · 4  · 4