HomeSecurityAtlassian Confluence: CISA and FBI encourage administrators to update immediately

Atlassian Confluence: CISA and FBI encourage administrators to update immediately

CISA, FBI, and MS-ISAC have warned network administrators to immediately update their Atlassian Confluence servers for a maximum allocation vulnerability that is being actively exploited in attacks.

See also: Atlassian Confluence: Abuse by state hackers

Atlassian Confluence

The critical privilege escalation vulnerability known as CVE-2023-22515affects Confluence Data Center and Server 8.0.0 and later versions and can be exploited remotely in low-sophistication attacks that do not require user interaction.

On October 4, when releasing security updates, Atlassian recommended that customers upgrade to one of the patched versions (i.e., 8.3.3 or later, 8.4.3 or later, 8.5.2 or later) as soon as possible, as the vulnerability had already been exploited by malicious actors in the real world as a zero-day.

Users who were unable to upgrade were encouraged to disable the affected areas or isolate them from internet. Administrators were also told to check for signs of compromise, including new or suspicious administrator accounts.

A week after the bug was added to the list of exploited vulnerabilities by CISA, Microsoft revealed that a Chinese-backed threat group known as Storm-0062 (also known as DarkShadow or Oro0lxy) had been exploiting the vulnerability as a zero-day since at least September 14, 2023.

"CISA, FBI, and MS-ISAC strongly encourage network administrators to immediately implement the updates provided by Atlassian," the three organizations warned.

See also: Atlassian lays off 5% of its staff

CISA FBI

Data collected by cybersecurity firm Greynoise suggests that exploitation of CVE-2023-22515 appears to be very limited so far. However, the exploitation landscape may soon change, with the release of PoC-oriented exploits developed by Valentin Lobstein and security engineer Owen Gong of Sophee , as well as full technical details of the vulnerability published by Rapid7 researchers last week.

“Due to the ease of exploitation, CISA, FBI, and MS-ISAC anticipate widespread exploitation of unpatched workspaces across government and private networks,” the joint statement warns.

It is absolutely essential to update Confluence servers immediately, given their history of attracting malicious actors. Previous attacks involving Linux botnet malware , crypto miners, and the AvosLocker and Cerber2021 ransomware attacks underscore the urgency of the problem.

Last year, CISA mandated federal agencies address another critical vulnerability in Confluence (CVE-2022-26138) that was actively exploited.

See also: Atlassian: Recent data leak comes from a third-party application

Recommended steps and best practices

1. Update Atlassian Confluence software 

Applying the patch begins with immediately updating your Atlassian Confluence software to the latest version. Updates are necessary because they often include fixes for security vulnerabilities. 

2. Confirm Security Settings 

After updating the software, you need to confirm that the security settings in Atlassian Confluence are configured correctly. Access permissions and access levels should be checked and configured appropriately. 

3. System Management Practice and Security Measures 

In addition to patching and verifying security settings, system management also requires prevention against hacking. Prevention includes documenting services, generating security reports regularly, and monitoring Atlassian security alerts. 

4. Preventive Incident Management 

It is vital to proactively manage any unusual activity or indication of a system breach. This may include monitoring system logs, generating vulnerability reports, and reviewing security strategies. 

5. Contacting Atlassian Support 

In case you encounter any uncertainty or difficulty, you should not hesitate to contact Atlassian support. Support staff is ready to assist and guide administrators in implementing the update.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS