{"cveID":"CVE-2023-22518","vendorProject":"Atlassian","product":"Confluence Data Center and Server","vulnerabilityName":"Atlassian Confluence Data Center and Server Improper Authorization Vulnerability","dateAdded":"2023-11-07","shortDescription":"Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","dueDate":"2023-11-28","knownRansomwareCampaignUse":"Known","notes":"https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html;  https://nvd.nist.gov/vuln/detail/CVE-2023-22518","cwes":["CWE-863"],"year":2023,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2023-22518","technique":"T1190","technique_name_at_mapping":"Exploit Public-Facing Application","mapping_type":"exploitation_technique","capability_group":"access_ctrl","comments":"CVE-2023-22518 is an improper authorization vulnerability. Adversaries have been seen using HTTP POST requests to upload maliciously-crafted zip files to Confluence WebServers to exploit this vulnerability. After exploitation, adversaries were observed doing local system information discovery and downloading malicious payloads.","references":["https://www.rapid7.com/blog/post/2023/11/06/etr-rapid7-observed-exploitation-of-atlassian-confluence-cve-2023-22518/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-22518","technique":"T1033","technique_name_at_mapping":"System Owner/User Discovery","mapping_type":"primary_impact","capability_group":"access_ctrl","comments":"CVE-2023-22518 is an improper authorization vulnerability. Adversaries have been seen using HTTP POST requests to upload maliciously-crafted zip files to Confluence WebServers to exploit this vulnerability. After exploitation, adversaries were observed doing local system information discovery, downloading malicious payloads,  ","references":["https://www.rapid7.com/blog/post/2023/11/06/etr-rapid7-observed-exploitation-of-atlassian-confluence-cve-2023-22518/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-22518","technique":"T1105","technique_name_at_mapping":"Ingress Tool Transfer","mapping_type":"secondary_impact","capability_group":"access_ctrl","comments":"CVE-2023-22518 is an improper authorization vulnerability. Adversaries have been seen using HTTP POST requests to upload maliciously-crafted zip files to Confluence WebServers to exploit this vulnerability. After exploitation, adversaries were observed doing local system information discovery, downloading malicious payloads,  ","references":["https://www.rapid7.com/blog/post/2023/11/06/etr-rapid7-observed-exploitation-of-atlassian-confluence-cve-2023-22518/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1033","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"System Owner/User Discovery","name_at_mapping":"System Owner/User Discovery","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":30,"has_detection_strategy":true},{"id":"T1105","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Ingress Tool Transfer","name_at_mapping":"Ingress Tool Transfer","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":87,"has_detection_strategy":true},{"id":"T1190","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploit Public-Facing Application","name_at_mapping":"Exploit Public-Facing Application","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":149,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":["1ddaa9a4-eb0b-4398-a9fe-7b018f9e23db","27d2cdde-9778-490e-91ec-9bd0be6e8cc6","a902d249-9b9c-4dc4-8fd0-fbe528ef965c","f8987c03-4290-4c96-870f-55e75ee377f4"],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}