{"id":1200205,"date":"2023-11-06T18:40:20","date_gmt":"2023-11-06T23:40:20","guid":{"rendered":"https:\/\/www.prime-wow.com\/?p=1200205"},"modified":"2023-11-06T18:40:20","modified_gmt":"2023-11-06T23:40:20","slug":"critical-vulnerability-in-atlassian-confluence-server-is-under-mass-exploitation","status":"publish","type":"post","link":"https:\/\/www.prime-wow.com\/?p=1200205","title":{"rendered":"Critical vulnerability in Atlassian Confluence server is under \u201cmass exploitation\u201d"},"content":{"rendered":"<div id=\"rss-wrap\">\n<figure class=\"intro-image intro-left\">\n  <img decoding=\"async\" src=\"https:\/\/www.prime-wow.com\/wp-content\/uploads\/2023\/11\/exploit-vulnerability-security-800x450-1.jpg\" alt=\"Critical vulnerability in Atlassian Confluence server is under &#x201C;mass exploitation&#x201D;\" \/><\/p>\n<p class=\"caption\" style=\"font-size:0.8em\"><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/07\/exploit-vulnerability-security.jpg\" class=\"enlarge-link\" data-height=\"563\" data-width=\"1000\">Enlarge<\/a> <\/p>\n<\/figure>\n<div><a name=\"page-1\" \/><\/div>\n<p>A critical vulnerability in Atlassian\u2019s Confluence enterprise server app that allows for malicious commands and reset servers is under active exploitation by threat actors in attacks that install ransomware, researchers said.<\/p>\n<p>\u201cWidespread exploitation of the CVE-2023-22518 authentication bypass vulnerability in Atlassian Confluence Server has begun, posing a risk of significant data loss,\u201d Glenn Thorpe, senior director of security research and detection engineering at security firm GreyNoise, <a href=\"https:\/\/infosec.exchange\/@ntkramer\/111358137312740939\">wrote on Mastodon<\/a> on Sunday. \u201cSo far, the attacking IPs all include Ukraine in their target.\u201d<\/p>\n<div class=\"centered-figure-container\">\n<div class=\"center\" style=\"width:400px\" \/><\/div>\n<p>He pointed to a <a href=\"https:\/\/viz.greynoise.io\/tag\/atlassian-confluence-server-authentication-bypass-attempt?days=3\">page<\/a> showing that between 12 am and 8 am on Sunday UTC (around 5 pm Saturday to 1 am Sunday Pacific Time), three different IP addresses began exploiting the critical vulnerability, which allows attackers to restore a database and execute malicious commands. The IPs have since stopped those attacks, but he said he suspected the exploits are continuing.<\/p>\n<\/div>\n<p><a href=\"https:\/\/arstechnica.com\/?p=1981826#p3\">Read 11 remaining paragraphs<\/a> | <a href=\"https:\/\/arstechnica.com\/?p=1981826&amp;comments=1\">Comments<\/a><\/p>\n<p>&#013;<br \/>\n&#013;<br \/>\nSource: Ars Technica &#8211; <a href=\"https:\/\/arstechnica.com\/?p=1981826\" target=\"_blank\" rel=\"noopener\">Critical vulnerability in Atlassian Confluence server is under \u201cmass exploitation\u201d<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Enlarge A critical vulnerability in Atlassian\u2019s Confluence enterprise server app that allows for malicious commands and reset servers is under active exploitation by threat actors in attacks that install ransomware, researchers said. \u201cWidespread exploitation of the CVE-2023-22518 authentication bypass vulnerability &hellip; <a href=\"https:\/\/www.prime-wow.com\/?p=1200205\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":1200206,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27,110],"tags":[73],"class_list":["post-1200205","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ars-technica","category-unfiltered-rss","tag-ars-technica"],"_links":{"self":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1200205","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1200205"}],"version-history":[{"count":0,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1200205\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/media\/1200206"}],"wp:attachment":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1200205"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1200205"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1200205"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}