Skip to content

Exploit for CVE-2023-22527 - Atlassian Confluence Data Center and Server

Notifications You must be signed in to change notification settings

yoryio/CVE-2023-22527

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

16 Commits
 
 
 
 

Repository files navigation

CVE-2023-22527

CVE-2023-22527 - Server-side Template Injection (SSTI) vulnerability allowing Remote Code Execution (RCE) In Confluence Data Center and Confluence Server

image

Products and Versions affected:

Product Affected Versions
Confluence Data Center and Server 8.0.x
8.2.x
8.3.x
8.4.x
8.5.0-8.5.3
  • CVSS: 10.0
  • Actively Exploited: YES
  • Patch: YES
  • Mitigation: NO

Help

usage: CVE-2023-22527.py [-h] -u URL [-c COMMAND]

options:
  -h, --help            show this help message and exit
  -u URL, --url URL     Atlassian Confluence Server URL
  -c COMMAND, --command COMMAND
                        Command to Execute

Example: python CVE-2023-22527.py -u https://10.10.12.2 -c whoami

Lab

You can use Try Hack Me's Room Confluence CVE-2023-22515 to test the exploit because it also runs a vulnerable version affected by CVE-2023-22527.

Vision of Atlassian Confluence Servers by SHADOWSERVER:

map

References

About

Exploit for CVE-2023-22527 - Atlassian Confluence Data Center and Server

Topics

Resources

Stars

Watchers

Forks

Packages

No packages published

Languages