Tag

Cve 2023 22527

All articles tagged with #cve 2023 22527

cybersecurity2 years ago

"Massive Wave of Attacks Targets Critical Atlassian Confluence RCE Vulnerability"

A critical security flaw affecting Atlassian Confluence Data Center and Server has been actively exploited by malicious actors, with nearly 40,000 exploitation attempts recorded within three days of its public disclosure. Tracked as CVE-2023-22527, the vulnerability allows unauthenticated attackers to achieve remote code execution on susceptible installations. The exploitation attempts, originating from over 600 unique IP addresses, are currently limited to testing callback attempts and 'whoami' execution, indicating opportunistic scanning for vulnerable servers. Over 11,000 Atlassian instances have been found accessible over the internet, raising concerns about the extent of vulnerability.

cybersecurity2 years ago

"Massive Exploitation of Critical Atlassian Confluence RCE Vulnerability"

More than 600 IP addresses are launching thousands of exploit attempts against a critical bug in out-of-date versions of Atlassian Confluence Data Center and Server, which can allow unauthenticated remote code execution (RCE) attacks. Despite Atlassian urging customers to update immediately, over 11,000 instances remain exposed on the internet, with more than 39,000 RCE attempts seen since January 19. Organizations with vulnerable instances are advised to assume a breach, patch, and take precautions, as this follows a string of critical flaws that have plagued the company in recent months.

cybersecurity2 years ago

"Atlassian Confluence RCE Flaw Exploited by Hackers"

Hackers are actively exploiting a critical remote code execution vulnerability, CVE-2023-22527, in outdated versions of Atlassian Confluence servers, with over 39,000 exploitation attempts recorded. The flaw allows unauthenticated remote attackers to execute code and affects versions 8.0.x to 8.5.3. Atlassian has released fixes for affected versions and advises administrators to update to secure versions released after December 5, 2023, while also recommending thorough system cleanup for potentially compromised instances.