iTnews Asia
  • Home
  • News
  • Data Centres

US law enforcement, cyber security orgs heighten calls to harden Confluence

US law enforcement, cyber security orgs heighten calls to harden Confluence

Amid ongoing exploits of patched vulnerability.

By Richard Chirgwin on Oct 18, 2023 2:55PM

Three American law enforcement and cyber security organisations have joined forces to call on organisations to patch the Atlassian Confluence Server and Data Centre vulnerability disclosed at the start of this month.

When patching CVE-2023-22515, Atlassian said the vulnerability may have already been exploited in some customer sites to create administrator accounts.

Last week Microsoft attributed the attacks to a Chinese actor.

Now, the FBI, the Cyber and Infrastructure Security Agency (CISA), and the Centre for Internet Security’s Multi-State Information Sharing and Analysis Center (MS-ISAC) have joined to author a paper [pdf] explaining the dangers in detail.

The joint cyber security advisory explained that “threat actors can change the Confluence server’s configuration to indicate the setup is not complete and use the /setup/setupadministrator.action endpoint to create a new administrator user."

“The vulnerability is triggered via a request on the unauthenticated /server-info.action endpoint,” the advisory stated.

It added: “Considering the root cause of the vulnerability allows threat actors to modify critical configuration settings, CISA, FBI, and MS-ISAC assess that the threat actors may not be limited to creating new administrator accounts”.

The three organisations said the bug is easy to exploit, so they expect “widespread exploitation of unpatched Confluence instances in government and private networks.”

They add that they’ve observed two command line tools, the cURL URL toolkit and Rclone data-sync utility, being used for post-exploit data exploitation.

The paper added that two user-agent strings have been observed in request headers to vulnerable systems: Python-requests/2.27.1, and curl/7.88.1, adding that “an increasing variation in user-agent strings is expected”.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
atlassian cisa confluence data centres fbi security

Related Articles

  • Edgnex to invest nearly SGD 3 billion in Jakarta AI data centre
  • SK Group and AWS to build South Korea’s largest AI data centre in Ulsan
  • The best way to outsmart your threat actors is to think like one
  • How cybercriminals are exploiting LLMs to harm your business
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Edgnex to invest nearly SGD 3 billion in Jakarta AI data centre

Edgnex to invest nearly SGD 3 billion in Jakarta AI data centre

SK Group and AWS to build South Korea’s largest AI data centre in Ulsan

SK Group and AWS to build South Korea’s largest AI data centre in Ulsan

STACK Infrastructure announces new data centre campus for Malaysia

STACK Infrastructure announces new data centre campus for Malaysia

STT GDC developing a new data centre campus in the Philippines

STT GDC developing a new data centre campus in the Philippines

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.