Wednesday, January 31, 2024

Server-Side Template Injection Vulnerability in Confluence Data Center and Server (CVE-2023-22527)

Introduction On January 16 2024, Atlassian issued a ​​significant alert on a critical Server-Side Template Injection (SSTI) vulnerability in Confluence Data Center and Server, identified as CVE-2023-22527. This issue found in older versions, poses a serious risk as it allows attackers without any authentication, to inject OGNL expressions. This means they could potentially run any [...]

The post Server-Side Template Injection Vulnerability in Confluence Data Center and Server (CVE-2023-22527) appeared first on Wallarm.

The post Server-Side Template Injection Vulnerability in Confluence Data Center and Server (CVE-2023-22527) appeared first on Security Boulevard.



source https://securityboulevard.com/2024/01/server-side-template-injection-vulnerability-in-confluence-data-center-and-server-cve-2023-22527/

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.