Oct. 19, 2023, 8:15 p.m. | Brendan Watters

Rapid7 Blog blog.rapid7.com

That Privilege Escalation Escalated Quickly


This release features a module leveraging CVE-2023-22515, a vulnerability in Atlassian’s on-premises Confluence Server first listed as a privilege escalation, but quickly recategorized as a “broken access control” with a CVSS score of 10. The exploit itself is very simple and easy to use

access access control atlassian broken access control confluence confluence server control cve cve-2023-22515 cvss easy escalation exploit features metasploit metasploit weekly wrapup privilege privilege escalation quickly release score server simple vulnerability weekly wrap-up

Security Analyst

@ Northwestern Memorial Healthcare | Chicago, IL, United States

GRC Analyst

@ Richemont | Shelton, CT, US

Security Specialist

@ Peraton | Government Site, MD, United States

Information Assurance Security Specialist (IASS)

@ OBXtek Inc. | United States

Cyber Security Technology Analyst

@ Airbus | Bengaluru (Airbus)

Vice President, Cyber Operations Engineer

@ BlackRock | LO9-London - Drapers Gardens