THREATPORT/VULNERABILITY/CVE-2023-22512
HIGH SEVERITY

CVE-2023-22512

Confluence Data Center vulnerability

CVSS
7.5
EPSS
13.7%
EPSS pct
96th
Exploited
No known
This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7.5, this vulnerability allows an unauthenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a vulnerable host (Confluence instance) connected to a network, which has no impact to confidentiality, no impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 7.19: Upgrade to a release greater than or equal to 7.19.14 Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.1 Confluence Data Center and Server 8.6 or above: No need to upgrade, you're already on a patched version See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives ]). This vulnerability was reported via our Bug Bounty program.
Affected vendor
Atlassian
Affected product
Confluence Data Center
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness type (CWE)
  • CWE-400 — Uncontrolled Resource Consumption
Published
2024-01-16

Risk analysis

Based on its CVSS vector, this vulnerability is exploitable over the network, low attack complexity, requiring no privileges, no user interaction. Successful exploitation leads to high impact to availability.

Its EPSS score of 13.7% reflects a moderate probability of exploitation activity in the wild over the next 30 days, placing it above 96% of all scored CVEs.

Check your external exposure to CVE-2023-22512

  • Confirm whether Atlassian Confluence Data Center is running on any internet-facing host or subdomain.
  • Match discovered service fingerprints against the version affected by CVE-2023-22512.
  • Prioritise remediation if the asset is public, business-critical, or near authentication/payment flows.

How ThreatPort helps with CVE-2023-22512

ThreatPort's external attack surface scanner checks your internet-facing assets — agentlessly, from the outside in — for the exposed services and versions that CVE-2023-22512 affects, then prioritises the finding by real risk using CISA KEV and FIRST.org EPSS.

Run a free external exposure scan

Are you exposed to CVE-2023-22512?

Run an instant, non-intrusive external scan to check your attack surface for CVE-2023-22512.

Start free scan

No credit card. Agentless.