漏洞描述 Confluence 是由 Atlassian 开发的企业级协作软件。2023年10月31日,Atlassian 官方披露 CVE-2023-22518 Atlassian Confluence Data Center & Server 权限提升漏洞。攻击者可构造恶意请求创建管理员,从而登录系统,最终可导致远程代码执行。
相关漏洞推荐 POC CVE-2017-5983: JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE) Atlassian Jira Software Data Center And Server 需授权 路径遍历漏洞 CVE-2019-3396: Atlassian Confluence Path Traversal Atlassian Confluence /json/setup-restore.action 文件上传漏洞(CVE-2023-22518) POC CVE-2015-8399: Atlassian Confluence <5.8.17 - Information Disclosure POC CVE-2017-9506: Atlassian Jira IconURIServlet - Cross-Site Scripting/Server-Side Request Forgery POC CVE-2018-20824: Atlassian Jira WallboardServlet <7.13.1 - Cross-Site Scripting POC CVE-2018-5230: Atlassian Jira Confluence - Cross-Site Scripting POC CVE-2019-11580: Atlassian Crowd and Crowd Data Center - Unauthenticated Remote Code Execution POC CVE-2019-11581: Atlassian Jira Server-Side Template Injection POC CVE-2019-3396: Atlassian Confluence Server - Path Traversal POC CVE-2019-3398: Atlassian Confluence Download Attachments - Remote Code Execution POC CVE-2019-3401: Atlassian Jira <7.13.3/8.0.0-8.1.1 - Incorrect Authorization