CVE Series: Confluence Authentication Vulnerability (CVE-2023-22515)
Confluence suffers from a Broken Access Control vulnerability that affects Data Center and Server versions 8.0.0 to 8.3.2, 8.4.0 to 8.4.2, and 8.5.0 to 8.5.1. Threat actors exploit this vulnerability to obtain administrator access to Confluence servers. Put on your Red Team hat to create your own malicious admin account leveraging this CVE!
Course Content
Confluence, a popular web-based wiki used by many corporations and developed by the software company, Atlassian, suffers from a Broken Access Control vulnerability that was reported in October of 2023. CVE-2023-22515 affects Confluence Data Center and Server versions 8.0.0 through to 8.3.2, 8.4.0 through to 8.4.2, and 8.5.0 through to 8.5.1. According to the Cybersecurity and Infrastructure Security Agency (CISA), threat actors have been exploiting this vulnerability in the wild to obtain administrator access to Confluence servers. In this course you’ll be putting on your Red Team hat to create your own malicious administrator account by leveraging this CVE!
Target Audience
This course is for seasoned red teamers, penetration testers, security and vulnerability assessment analysts, and system administrators who want to know how to exploit and protect against the latest vulnerabilities impacting enterprise systems.
Course Level
Intermediate
Prerequisites
Basic knowledge of Python as a programming language as well as functional knowledge of web applications.
Helpful Links
By the end of this course, you should be able to: