CVE-2023-22527
CRITICALA template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using…
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Description
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action.
Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.
Affected Products
confluence data centeratlassianconfluence serveratlassianResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
A template injection vulnerability on older versions of Confluence Data …
A template injection vulnerability on older versions of Confluence Data …
A template injection vulnerability on older versions of Confluence Data …
A template injection vulnerability on older versions of Confluence Data …
A template injection vulnerability on older versions of Confluence Data …
A template injection vulnerability on older versions of Confluence Data …
A template injection vulnerability on older versions of Confluence Data …
A template injection vulnerability on older versions of Confluence Data …
A template injection vulnerability on older versions of Confluence Data …
A template injection vulnerability on older versions of Confluence Data …
Frequently Asked Questions
Is CVE-2023-22527 in your stack?
O3 detects CVE-2023-22527 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.