Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-22515 — Step-by-step exploit walkthrough for CVE-2023-22515, a critical broken access control vulnerability in Atlassian Confluence Server and Data Center, enabling remote admin account creation. | Kitploit
Tools/GitHubGitHub/tranphuc2005/cve-2023-22515
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHubtranphuc2005/cve-2023-22515

CVE-2023-22515

Step-by-step exploit walkthrough for CVE-2023-22515, a critical broken access control vulnerability in Atlassian Confluence Server and Data Center, enabling remote admin account creation.

View Repository
11 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-22515

Key Information about CVE-2023-22515

  • Affected Product: Atlassian Confluence Data Center & Confluence Server.

  • Disclosure Date: 04/10/2023.

  • Severity: Critical (CVSS ~ 10.0).

  • Vulnerability Type: Broken Access Control / Improper Authorization → allows an attacker to remotely create an admin account.

  • The flaw resides in the Confluence setup mechanism

  • Impact: Confluence Data Center & Server 8.0.0 → 8.5.1.

Vulnerability Discovery

  • First, when installing Confluence, there is a configuration step for the server to operate, e.g., DATABASE connection, user creation, etc. These actions are performed through a web browser using /setup/ URL paths. The final configuration step is /setup/setupadministrator.action.
  • After completion, these settings are no longer callable. If we try to call them, an error message is displayed

1

  • This originates from one of the interceptors, SetupCheckInterceptor, defined in struts.xml

    • struts.xml is the central configuration file for Struts.

    • It defines how Confluence maps URL → Action class → View template.

    • It also declares interceptors (classes that intercept request processing before/after running an action).

1

Inside SetupCheckInterceptor, it calls BootstrapUtils.getBootstrapManager().isSetupComplete()

public String intercept(ActionInvocation actionInvocation) throws Exception {
    if (BootstrapUtils.getBootstrapManager().isSetupComplete() && ContainerManager.isContainerSetup())
        return "alreadysetup"; 
    return actionInvocation.invoke();
}

Explanation

  • BootstrapUtils.getBootstrapManager().isSetupComplete()
    → Checks whether Confluence has completed the setup process (via wizard, license input, admin user creation).

  • ContainerManager.isContainerSetup()
    → Checks whether the Spring IoC container has been fully initialized.

  • If both conditions are true:
    → The system is fully set up → the interceptor immediately returns "alreadysetup".
    → It does not allow the action (typically setup actions like SetupDatabaseAction, SetupLicenseAction, …) to proceed.

  • If setup is not complete:
    → Calls actionInvocation.invoke() → i.e., continues to execute the user-requested action.

getBootstrapManager() → usually returns DefaultAtlassianBootstrapManager, which manages all core configuration information during setup.

  • In DefaultAtlassianBootstrapManager.isSetupComplete, we can see that the application configuration method isSetupComplete is called to check whether setup is complete.

1

=> If we can make isSetupComplete = False, then SetupCheckInterceptor will not return "alreadysetup" and /setup/setupadministrator.action will become accessible.

Below we have a ServerInfoAction

  • ServerInfoAction = a public action in Confluence → allows any user to call it without login or CSRF token. When executed, it simply returns "success" → mapped to a template that displays server information.

1

  • It extends ConfluenceActionSupport.
  • In ConfluenceActionSupport, we see that getBootstrapStatusProvider returns BootstrapStatusProviderImpl, the instance we are looking for.

1

  • In BootstrapStatusProviderImpl, there is getApplicationConfig to return the application configuration.

1

  • Finally, inside ApplicationConfig, we can see that it implements setSetupComplete check.

1

  • Combining the above, we can deduce a chain of methods to set setSetupComplete = false
getBootstrapStatusProvider(). getApplicationConfig (). setSetupComplete ( false );
  • XWorks2 allows us to execute such getter/setter chains; we can craft an HTTP parameter to implement the above method call chain using the notation required by XWorks2.
bootstrapStatusProvider.applicationConfig.setupComplete=false
  • We will exploit /server-info.action, a URL in Confluence handled by ServerInfoAction because it is a public endpoint that does not require authentication.
/server-info.action?bootstrapStatusProvider.applicationConfig.setupComplete=false

1

Let's check the Debug:

  • setupComplete (parameter passed to method)
    → false
    This means the method is being called with parameter false.

  • this.setupComplete (instance variable of ApplicationConfig object)
    → true (before assignment).

  • After the command executes, this.setupComplete becomes false.

1

  • After completing the above step, let's try to access the endpoint /setup/setupadministrator.action and succeed.

1

  • After creation, log in and verify the privileges.

1

Download Tool