To access material, start machines and answer questions login.
Set up your virtual environment
On October 4th, 2023, Atlassian released a security advisory (opens in new tab) regarding -2023-22515, a broken access control vulnerability, with an assigned score of 10.0. The vulnerability was introduced in version 8.0.0 of Confluence Server and Data Center editions and is present in versions <8.3.3, <8.4.3, <8.5.2. According to Atlassian, the vulnerability has already been exploited in the wild.
An attacker can exploit the vulnerability to create an additional account in Confluence with full administrative privileges. The attacker needs no prior information to exploit the vulnerability. The vulnerability is believed to enable other unknown attack vectors and should be patched as soon as possible.
Starting the VM
To deploy the attached VM, press the green Start Lab Machine button at the top of the task.
Your VM has a clean trial installation of Atlassian Confluence Data Center edition running on http://MACHINE_IP:8090, which will serve as our target. The machine may take around 5 minutes to boot up.
Ready to learn Cyber Security?
The Confluence CVE-2023-22515 room is only available for Premium or Max subscribers. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in

