Oct. 27, 2023, 6:46 p.m. | Christopher Granleese

Rapid7 Blog blog.rapid7.com

New module content (4)


Atlassian Confluence Data Center and Server Authentication Bypass via Broken Access Control


Authors: Emir Polat and Unknown

Type: Auxiliary

Pull request: #18447 contributed by emirpolatt

Path: admin/http/atlassian_confluence_auth_bypass

AttackerKB reference: CVE-2023-22515


Description: This adds an exploit for CVE-2023-22515, which is an authentication

access access control admin atlassian atlassian confluence authentication authentication bypass authors broken access control bypass center confluence confluence data center contributed control cve cve-2023-22515 data data center exploit http metasploit metasploit weekly wrapup path reference request server weekly wrap-up

Security Analyst

@ Northwestern Memorial Healthcare | Chicago, IL, United States

GRC Analyst

@ Richemont | Shelton, CT, US

Security Specialist

@ Peraton | Government Site, MD, United States

Information Assurance Security Specialist (IASS)

@ OBXtek Inc. | United States

Cyber Security Technology Analyst

@ Airbus | Bengaluru (Airbus)

Vice President, Cyber Operations Engineer

@ BlackRock | LO9-London - Drapers Gardens