# N/A
## 漏洞概述
Atlassian 发现一个由少数客户报告的漏洞,外部攻击者可能利用此漏洞在公开访问的 Confluence Data Center 和 Server 实例中创建未经授权的 Confluence 管理员账户并获取 Confluence 实例的访问权限。
## 影响版本
- Confluence Data Center
- Confluence Server (公开访问的实例)
## 细节
外部攻击者可能利用一个此前未知的漏洞,创建未经授权的 Confluence 管理员账户并访问 Confluence 实例。
## 影响
- 被公开访问的 Confluence Data Center 和 Server 实例受到影响。
- Atlassian Cloud 站点不受此漏洞影响。
- 如果 Confluence 站点通过 atlassian.net 域访问,则由 Atlassian 托管,不受此漏洞影响。
# | POC 描述 | 源链接 | 神龙链接 |
---|---|---|---|
1 | Scanner for CVE-2023-22515 - Broken Access Control Vulnerability in Atlassian Confluence | https://github.com/ErikWynter/CVE-2023-22515-Scan | POC详情 |
2 | Poc for CVE-2023-22515 | https://github.com/j3seer/CVE-2023-22515-POC | POC详情 |
3 | CVE-2023-22515: Confluence Broken Access Control Exploit | https://github.com/Chocapikk/CVE-2023-22515 | POC详情 |
4 | Confluence未授权添加管理员用户(CVE-2023-22515)漏洞利用工具 | https://github.com/ad-calcium/CVE-2023-22515 | POC详情 |
5 | CVE-2023-22515 - Broken Access Control Vulnerability in Confluence Data Center and Server | https://github.com/kh4sh3i/CVE-2023-22515 | POC详情 |
6 | Confluence未授权添加管理员用户漏洞利用脚本 | https://github.com/sincere9/CVE-2023-22515 | POC详情 |
7 | Confluence Data Center & Server 权限提升漏洞 Exploit | https://github.com/Le1a/CVE-2023-22515 | POC详情 |
8 | Confluence Broken Access Control | https://github.com/Vulnmachines/confluence-cve-2023-22515 | POC详情 |
9 | iveresk-CVE-2023-22515 | https://github.com/iveresk/CVE-2023-22515 | POC详情 |
10 | Confluence后台rce | https://github.com/youcannotseemeagain/CVE-2023-22515_RCE | POC详情 |
11 | cve-2023-22515的python利用脚本 | https://github.com/DsaHen/cve-2023-22515-exp | POC详情 |
12 | CVE-2023-22515 (Confluence Broken Access Control Exploit) | https://github.com/joaoviictorti/CVE-2023-22515 | POC详情 |
13 | CVE-2023-22515 | https://github.com/C1ph3rX13/CVE-2023-22515 | POC详情 |
14 | CVE-2023-22515 | https://github.com/AIex-3/confluence-hack | POC详情 |
15 | Server Broken Access Control in Confluence - CVE-2023-22515 | https://github.com/LucasPDiniz/CVE-2023-22515 | POC详情 |
16 | 配合 CVE-2023-22515 后台上传jar包实现RCE | https://github.com/aaaademo/Confluence-EvilJar | POC详情 |
17 | None | https://github.com/edsonjt81/CVE-2023-22515-Scan. | POC详情 |
18 | Confluence broken access control to code execution | https://github.com/INTfinityConsulting/cve-2023-22515 | POC详情 |
19 | A simple exploit for CVE-2023-22515 | https://github.com/CalegariMindSec/Exploit-CVE-2023-22515 | POC详情 |
20 | Atlassian Confluence Data Center and Server Broken Access Control Vulnerability | https://github.com/rxerium/CVE-2023-22515 | POC详情 |
21 | NSE script for checking the presence of CVE-2023-22515 | https://github.com/fyx1t/NSE--CVE-2023-22515 | POC详情 |
22 | This script will inform the user if the Confluence instance is vulnerable, but it will not proceed with the exploitation steps. | https://github.com/s1d6point7bugcrowd/CVE-2023-22515-check | POC详情 |
23 | NSE script to check if app is vulnerable to cve-2023-22515 | https://github.com/xorbbo/cve-2023-22515 | POC详情 |
24 | Vulnerability checking tool via Nmap Scripting Engine | https://github.com/spareack/CVE-2023-22515-NSE | POC详情 |
25 | CVE 2023-22515 | https://github.com/Onedy1703/CVE-2023-22515 | POC详情 |
26 | CVE 2023-22515 | https://github.com/Onedy1703/CVE-2023-22515-Confluence | POC详情 |
27 | None | https://github.com/vivigotnotime/CVE-2023-22515-Exploit-Script | POC详情 |
28 | Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-22515.yaml | POC详情 |
29 | None | https://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/Atlassian%20Confluence%20server-info.action%20%E5%B1%9E%E6%80%A7%E8%A6%86%E7%9B%96%E5%AF%BC%E8%87%B4%E6%9D%83%E9%99%90%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E%20CVE-2023-22515.md | POC详情 |
30 | https://github.com/vulhub/vulhub/blob/master/confluence/CVE-2023-22515/README.md | POC详情 | |
31 | CVE-2023-22515 (Confluence Broken Access Control Exploit) | https://github.com/killvxk/CVE-2023-22515-joaoviictorti | POC详情 |
暂无评论