National Cyber Warfare Foundation (NCWF) Forums


Server-Side Template Injection Vulnerability in Confluence Data Center and Server (CVE-2023-22527)


0 user ratings
2024-01-31 07:10:00
milo
Blue Team (CND)

 - archive -- 

Introduction On January 16 2024, Atlassian issued a ​​significant alert on a critical Server-Side Template Injection (SSTI) vulnerability in Confluence Data Center and Server, identified as CVE-2023-22527. This issue found in older versions, poses a serious risk as it allows attackers without any authentication, to inject OGNL expressions. This means they could potentially run any [...]


The post Server-Side Template Injection Vulnerability in Confluence Data Center and Server (CVE-2023-22527) appeared first on Wallarm.


The post Server-Side Template Injection Vulnerability in Confluence Data Center and Server (CVE-2023-22527) appeared first on Security Boulevard.



Jaweed Metz

Source: Security Boulevard
Source Link: https://securityboulevard.com/2024/01/server-side-template-injection-vulnerability-in-confluence-data-center-and-server-cve-2023-22527/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



© Copyright 2012 through 2024 - National Cyber War Foundation - All rights reserved worldwide.