Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » Key Convergence RCEs Being Actively Exploited
    Cyber Security

    Key Convergence RCEs Being Actively Exploited

    techempireBy techempire2 Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportJanuary 23, 2024Editorial DepartmentVulnerabilities/cyberattacks

    cyber attack

    Within three days of public disclosure, malicious actors have begun actively exploiting recently disclosed critical security vulnerabilities affecting Atlassian Confluence data centers and Confluence servers.

    Tracked as CVE-2023-22527 (CVSS Score: 10.0), this vulnerability affects outdated software versions and could allow an unauthenticated attacker to achieve remote code execution on a vulnerable installation.

    This flaw affects Confluence Data Center and Server 8 versions released before December 5, 2023, as well as 8.4.5.

    But just days after the vulnerability became public knowledge, nearly 40,000 exploit attempts against CVE-2023-22527 were recorded as early as January 19 from more than 600 unique IP addresses, according to both parties. Shadow Server Foundation and DFIR report.

    The activity is currently limited to “testing callback attempts and ‘whoami’ executions,” suggesting that threat actors are opportunistically scanning vulnerable servers for subsequent exploitation.

    The majority of attacker IP addresses came from Russia (22,674), followed by Singapore, Hong Kong, the United States, China, India, Brazil, Taiwan, Japan, and Ecuador.

    Internet security

    As of January 21, 2024, more than 11,000 Atlassian instances have been found to be accessible over the Internet, but it is unclear how many of these instances are vulnerable to CVE-2023-22527.

    “CVE-2023-22527 is a critical vulnerability within Atlassian Confluence servers and data centers,” ProjectDiscovery researchers Rahul Maini and Harsh Jaiswal said in a technical analysis of the flaw.

    “This vulnerability could allow an unauthenticated attacker to inject OGNL expressions into a Confluence instance, thereby executing arbitrary code and system commands.”

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.