Cloudflare Blocks Critical Confluence Zero-Day for All Customers

Atlassian published details on October 4, 2023, at 13:00 UTC about a zero-day vulnerability in Confluence Data Center and Server, tracked as CVE-2023-22515. The flaw is a privilege escalation vulnerability that Atlassian has assessed as critical, although a CVSS score has not yet been released.

Exploitation of CVE-2023-22515 allows an attacker to access public Confluence Data Center and Server instances and create unauthorized administrator accounts, potentially gaining full control of the affected instance.

Proactive Protection Deployed

Cloudflare received advance warning of the vulnerability before Atlassian's advisory was published. The company collaborated with Atlassian to apply protective WAF managed rules for all customers, including those on the Free plan, with protection enabled by default. The Cloudflare WAF team released these emergency rules on October 3, 2023, at 14:00 UTC to address the first variant of the vulnerability observed in real traffic.

Additional details about affected Confluence Server versions are available in the official Atlassian security advisory.