T1190 Exploit Public-Facing Application T1078 Valid Accounts T1136 Create Account
Malicious activity originated from external IP address 43.130.1.222 targeting the Confluence Data Center server (IP address 172.16.17.234).
The alert SOC235 Atlassian Confluence Broken Access Control 0-Day CVE-2023-22515 triggered due to exploitation attempts against a vulnerable Confluence instance. Logs confirm successful exploitation of CVE-2023-22515, allowing the attacker to bypass setup protections and create an unauthorized administrator account. HTTP logs show sequential requests using curl to access /server-info.action, followed by POST requests to /setup/setupadministrator.action and /setup/finishsetup.action, indicating completion of the setup abuse process. The server is running Confluence version 8.0.3, which is confirmed vulnerable. Threat intelligence confirms the source IP is malicious.
Nov 09 2023 09:47 AM
Target Hostname: Confluence Data Center Destination IP Address: 172.16.17.234 Source IP Address: 43.130.1.222 Affected application: Atlassian Confluence Data Center v8.0.3 Log file: C:\Program Files\Atlassian\Confluence\logs\conf_access_log.2023-11-09.log
The alert was triggered due to exploitation of a known critical vulnerability (CVE-2023-22515) affecting Confluence. Investigation confirmed the instance was vulnerable and the attacker successfully abused the setup functionality to create an unauthorized administrator account. This represents a confirmed compromise of a public-facing application. The incident was contained and escalated to Tier 2 for further remediation, including patching, account review, and system integrity validation.