Australian software company Atlassian has warned administrators to immediately update their public Confluence programs against a critical security vulnerability that could lead to data loss if successfully exploited.
See also: Atlassian Confluence: CISA and FBI encourage administrators to update immediately

It is described as an improper authorization vulnerability affecting all versions of Confluence Data Center and Confluence Server software. This vulnerability poses a critical risk for publicly accessible instances. It is identified as CVE-2023-22518.
While malicious actors could exploit the flaw to corrupt data on affected servers, the flaw does not impact privacy as it cannot be exploited to steal data. Atlassian Cloud websites accessed through the atlassian.net are not affected by this vulnerability.
“As part of our ongoing security assessment processes, we have found that Confluence Data Center and Server customers are vulnerable to significant data loss if exploited by an unauthorized attacker ,” said Bala Sathiamurthy, Atlassian’s Chief Information Security Officer (CISO).
There are currently no reports of active exploitation. However, customers should take immediate steps to protect their connections. The company has patched the critical vulnerability CVE-2023-22518 in Confluence Data Center and Server versions 7.19.16, 8.3.4, 8.4.4, 8.5.3, and 8.6.1.
Atlassian warned administrators to immediately upgrade to a patched version and, if that is not possible, to implement mitigation measures, including backing up out-of-date programs and restricting Internet until they are upgraded.
See also: Atlassian Confluence: Abuse by state hackers
“The company said that instances accessible to the public internet, including those with authentication, should be restricted from external network access until you can update the system.“
Earlier this month, CISA, the FBI, and MS-ISAC warned network administrators to immediately update Atlassian Confluence servers for an elevation of privilege vulnerability that is being actively exploited and identified as CVE-2023-22515.

“Due to the ease of exploitation, CISA, FBI, and MS-ISAC anticipate widespread exploitation of unpatched instances of Confluence across government and private networks,” the joint statement warned.
Microsoft revealed that the Chinese-backed threat group Storm-0062 (also known as DarkShadow or Oro0lxy) has been exploiting the flaw as a zero-day since at least September 14 , 2023
Patching vulnerable Confluence servers as soon as possible is of paramount importance, as they have previously been the target of widespread attacks that promoted Linux botnet, cryptominers, and the AvosLocker and Cerber2021 ransomware.
See also: Atlassian: Fixes critical Confluence zero-day bug
To prevent or mitigate the impact of this critical vulnerability in Atlassian Confluence, there are a few steps you can take. First, it's important to be aware of the vulnerability and its impact on your system. You can visit Atlassian's website for more information and updates about the vulnerability.
Next, you should check whether the version of Confluence you are using is affected by the vulnerability. Atlassian provides detailed instructions for checking your version and detecting the vulnerability. If you find that your version is affected, you should proceed to update Confluence to the latest secure version.
Additionally, it is a good practice to regularly apply security updates and patches provided by Atlassian. This will help prevent any future vulnerabilities and keep your system secure. Additionally, you should monitor your system security and take steps to protect your sensitive data.
Finally, it is important to educate your users on security best practices and inform them of any security threats that may exist within Confluence. By raising awareness and making users aware, you can reduce the risk associated with vulnerability.
Source: bleepingcomputer
