Security

Patches

Stop what you’re doing and patch this critical Confluence flaw, warns Atlassian

Risk of ‘significant data loss’ for on-prem customers


Atlassian has told customers they “must take immediate action” to address a newly discovered flaw in its Confluence collaboration tool.

An advisory issued on October 31st warns of CVE-2023-22518, described as an “improper authorization vulnerability in Confluence Data Center and Server”, the on-prem versions of Atlassian’s products.

All versions of Confluence are susceptible to the bug, which Atlassian rates at 9.1/10 severity on the ten-point Common Vulnerability Scoring System.

The Australian vendor hasn’t detailed the nature of the flaw or how it can facilitate data loss. The company has said it’s not seen any exploits. Perhaps explaining the flaw would tip off attackers.

The fix is simple: upgrade immediately to version of Confluence that have patched the mysterious flaw. Confluence versions 7.19.16, 8.3.4, 8.4.4, 8.5.3, 8.6.1, or any version later than those releases, will do the job.

Before you upgrade, Atlassian suggests disconnecting Confluence instances from the public internet. If that’s not doable, the vendor advises restricting external network access until patches are applied.

Users of SaaS-y Confluence in Atlassian’s cloud have nothing to worry about.

The flaw is the second urgent Confluence bug to have emerged in October. CVE-2023-22515, announced on October 4th, allowed miscreants to create and abuse Confluence admin accounts.

Attackers jumped at the chance to exploit the flaw, leading US authorities to urge rapid patching.

The company also reported a critical flaw in its BitBucket product in August 2022.

Another factor to consider is that support for the Server version of Confluence will end on February 14th, 2024.

When The Register considered that deadline, Atlassian explained it considers itself a cloud-first company and explained that it prioritises the SaaS version of its products. Readers responded with concerns about the cost of migrating to either Atlassian’s Data Center and fears it will receive less attention than the Atlassian cloud.

Two critical flaws in a month certainly suggest self-hosted Confluence is a high-maintenance option, and that the A-Cloud is a more comfortable proposition. Atlassian agrees with that position, but also kept its Data Center products alive out of recognition that not every customer is comfortable in the cloud.

And today they’re not comfortable outside it, either. ®

Send us news
2 Comments

Tired of airport security queues? SQL inject yourself into the cockpit, claim researchers

Infosec hounds say they spotted vulnerability during routine travel in the US

Atlassian CEO's idea to build 4,000-kilometer extension cord plugged in

Giant solar farm in Australia will make 'leccy that flows under the ocean to Singapore

AMD reverses course: Ryzen 3000 CPUs will get SinkClose patch after all

Still no love for 1000- or 2000-series

Multiple flaws in Microsoft macOS apps unpatched despite potential risks

Windows giant tells Cisco Talos it isn't fixing them

AMD won’t patch Sinkclose security bug on older Zen CPUs

Kernel mode not good enough for you? Maybe you'll like SMM of this

Atlassian softens its cloud-first approach for remaining on-prem customers

Happy to have 'em go hybrid as it wises up to the enterprise

Using 1Password on Mac? Patch up if you don’t want your Vaults raided

Hundreds of thousands of users potentially vulnerable

If you give Copilot the reins, don't be surprised when it spills your secrets

'All of the defaults are insecure' Zenity CTO claims

Devices with insecure SSH services are everywhere, say infosec duo

'Serendipitous' discovery may have you second guessing your appliances

SAP Core AI bugs allowed access to internal network servers, say researchers

Wiz infoseccers able to promote themselves from humble customer to full-blown admin

UK plans to revamp national cyber defense tools are already in motion

Work aims to build on the success of NCSC's 2016 initiative – and private sector will play a part

Ransomware gangs are loving this dumb but deadly make-me-admin ESXi vulnerability

Get those patches applied – all the big dogs are abusing it