Australian software company Atlassian has released urgent security updates to fix a very serious zero-day vulnerability in its Confluence Data Center and Server software . The vulnerability is already being used in attacks.

The term “zero-day” refers to a software vulnerability that is known to attackers, but has not yet been patched by the software. This means that attackers can exploit the vulnerability before it is patched. Zero-day bugs pose a significant threat to the security of networks and systems, as they can be used to create uncontrolled access, steal data, or cause other damage.
See also: Apple fixes zero-day that allows attacks on iPhone/iPad
“Atlassian has been made aware of an issue reported by some customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized accounts and gain access to Confluence instances,” says .
The company explains that Atlassian Cloud sites are not affected by this vulnerability. “ If the Confluence site is accessible through an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue .”
The zero-day vulnerability is tracked as CVE-2023-22515 and could allow elevation of privilege. It affects Confluence Data Center and Server 8.0.0 and later versions and is described as a remote exploitable vulnerability, with no user interaction required.
See also: Qualcomm: Hackers exploit 3 zero-days in GPU and DSP programs
Customers using vulnerable versions of Confluence Data Center and Server are advised to upgrade their installations to one of the patched versions (i.e., 8.3.3 or later, 8.4.3 or later, 8.5.2 or later) as soon as possible.
Atlassian also urges customers to disable vulnerable installations or isolate them from access internetif immediate remediation is not possible.

Administrators can reduce the chances of the vulnerability being exploited by preventing access to /setup/* endpoints on Confluence instances.
Administrators are advised to check for signs of tampering
The company recommends checking all Confluence instances for possible suspicious activity:
- new members in the confluence-administrator group
- new user accounts
- requests for /setup/*.action in network access logs
- presence of /setup/setupadministrator.action in exception message in atlassian-confluence-security.log in Confluence home directory
See also: Security updates for Microsoft Edge, Teams and Skype due to zero-days
With the release of an update, attackers may look for the patched components to speed up the creation of an exploit.
The Confluence update, which fixes the new critical vulnerability, is already available for users to install .Atlassian strongly recommends applying the update as soon as possible.
The immediate implementation of security updates for Confluence servers is particularly important, especially considering previous attacks that used the AvosLocker and Cerber2021 ransomware , Linux botnet malware , and crypto miners.
Source: www.bleepingcomputer.com
