References https://www.h3c.com/cn/d_202310/1949401_30003_0.htm https://cloud.tencent.com/developer/article/2353929 https://zhuanlan.zhihu.com/p/661867323 https://www.ctfiot.com/144843.html https://blog.csdn.net/qq_53003652/article/details/133868104 https://www.secrss.com/articles/59371 https://developer.aliyun.com/article/1465326 https://www.aqtd.com/nd.jsp?id=5115 https://rivers.chaitin.cn/blog/cq956p90lnechd244tig http://www.bmth666.cn/2023/11/05/CVE-2023-22515-Confluence-Broken-Authentication/index.html https://www.chaosec.com/?p=1460 https://www.yijinglab.com/specialized/20231122160143 https://cn-sec.com/archives/2109941.html https://blog.51cto.com/u_15302226/10667355 https://cve.imfht.com/detail/CVE-2023-22515 https://baike.baidu.com/en/item/Confluence/1457965 https://t0ngmystic.com/sec/cve-2023-22515-confluence%E8%AE%BF%E9%97%AE%E6%8E%A7%E5%88%B6%E6%BC%8F%E6%B4%9E-%E4%BB%BB%E6%84%8F%E7%AE%A1%E7%90%86%E5%91%98%E5%88%9B%E5%BB%BA/ https://github.com/ad-calcium/CVE-2023-22515 https://confluence.atlassian.com/security/cve-2023-22515-broken-access-control-vulnerability-in-confluence-data-center-and-server-1295682276.html https://nvd.nist.gov/vuln/detail/cve-2023-22515 https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-289a https://blog.qualys.com/vulnerabilities-threat-research/2023/11/15/atlassian-confluence-broken-access-control-vulnerability-cve-2023-22515 https://medium.com/@owaisalikhan081/soc235-atlassian-confluence-broken-access-control-0-day-cve-2023-22515-a420cf431747 https://www.rapid7.com/blog/post/2023/10/04/etr-cve-2023-22515-zero-day-privilege-escalation-in-confluence-server-and-data-center/ https://www.vicarius.io/vsociety/posts/understanding-the-confluence-vulnerability-cve-2023-22515 https://github.com/Chocapikk/CVE-2023-22515 https://www.sentinelone.com/vulnerability-database/cve-2023-22515/ https://www.greynoise.io/blog/cve-2023-22515-critical-privilege-escalation-vulnerability-in-atlassians-confluence https://cve.imfht.com/poc_detail/29dd47f4376833661cc48fd4542e277f814d9629
Related VulnerabilitiesPoCCVE-2026-27826: mcp-atlassian < 0.17.0 - Server-Side Request ForgeryMCP Atlassian 存在SSRF漏洞(CVE-2026-27826)PoCconfluence-xslt-macro-ssrf: Atlassian Confluence XSLT Macro - Server-Side Request ForgeryPoCCVE-2017-5983: JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE)Atlassian Jira Software Data Center And Server 需授权 路径遍历漏洞CVE-2019-3396: Atlassian Confluence Path TraversalAtlassian Confluence /json/setup-restore.action 文件上传漏洞(CVE-2023-22518)PoCCVE-2015-8399: Atlassian Confluence <5.8.17 - Information DisclosurePoCCVE-2017-9506: Atlassian Jira IconURIServlet - Cross-Site Scripting/Server-Side Request ForgeryPoCCVE-2018-20824: Atlassian Jira WallboardServlet <7.13.1 - Cross-Site ScriptingPoCCVE-2018-5230: Atlassian Jira Confluence - Cross-Site Scripting