Atlassian disclosed a critical Confluence vulnerability, CVE-2023-22515, that can let an attacker create unauthorized administrator accounts and potentially take over the entire environment. Atlassian assessed the flaw as likely falling between 9.0 and 10.0 in severity and urged defenders to restrict access to the vulnerable component until patches could be applied. Authorities warned that any internet-exposed vulnerable instance showing even minor anomalies should be treated as potentially compromised, with indicators including unexpected additions to the confluence-administrators group, unexplained user creation, requests to /setup/*.action, and evidence of /setup/setupadministrator.action in atlassian-confluence-security.log. Subsequent analysis indicated the flaw might also be exploitable without creating an administrator account, including through /server-info.action, and Microsoft reported signs of exploitation dating back to mid-September 2023.
JetBrains later released fixes for critical TeamCity authentication bypass vulnerabilities affecting all on-premises server installations through version 2023.11.3, resolving them in 2023.11.4. The company said an unauthenticated attacker could send specially crafted HTTP(S) requests to bypass authentication or gain administrator-level access, and exploitation attempts had already been observed. JetBrains updated and checked its cloud-hosted service, while defenders running on-premises TeamCity were told to patch immediately and review systems for compromise after updating, underscoring the ongoing risk from exposed enterprise collaboration and CI/CD platforms that can be seized through admin-level access flaws.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
At the time of JetBrains' March 2024 advisory, exploitation attempts had already been observed against the TeamCity authentication bypass flaws. Defenders were advised to update and investigate systems for signs of compromise.
JetBrains released TeamCity version 2023.11.4 to fix authentication bypass vulnerabilities affecting on-premises TeamCity servers up to version 2023.11.3. The company said cloud-hosted servers had already been updated and checked.
On 2024-01-16, Atlassian released security updates for multiple products including Confluence, Bitbucket, Jira, Bamboo, and Crowd. The advisory highlighted CVE-2023-22527 in Confluence as the most critical issue and said it had already been observed in December 2023, while supported Confluence versions were already fixed through regular updates.
An update citing Rapid7 analysis said CVE-2023-22515 might be exploitable without creating an administrator account, including via the /server-info.action path. This expanded the known technical understanding of how the flaw could be abused.
Atlassian disclosed CVE-2023-22515 affecting Confluence, a critical vulnerability that could let attackers create unauthorized administrator accounts and potentially take over the environment. Temporary mitigation guidance included restricting access to the vulnerable component until security updates could be installed.
A later update to the advisory said Microsoft researchers found signs that CVE-2023-22515 had been exploited as early as 2023-09-14. Microsoft also shared four IP addresses associated with exploit-related traffic.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
kyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.