Oct. 27, 2023, 6:46 p.m. | Christopher Granleese

Rapid7 Blog blog.rapid7.com

New module content (4)


Atlassian Confluence Data Center and Server Authentication Bypass via Broken Access Control


Authors: Emir Polat and Unknown

Type: Auxiliary

Pull request: #18447 contributed by emirpolatt

Path: admin/http/atlassian_confluence_auth_bypass

AttackerKB reference: CVE-2023-22515


Description: This adds an exploit for CVE-2023-22515, which is an authentication

access access control admin atlassian atlassian confluence authentication authentication bypass authors broken access control bypass center confluence confluence data center contributed control cve cve-2023-22515 data data center exploit http metasploit metasploit weekly wrapup path reference request server weekly wrap-up

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Consultant Sécurité SI Gouvernance - Risques - Conformité H/F - Strasbourg

@ Hifield | Strasbourg, France

Lead Security Specialist

@ KBR, Inc. | USA, Dallas, 8121 Lemmon Ave, Suite 550, Texas

Consultant SOC / CERT H/F

@ Hifield | Sèvres, France