DEV Community

endoflife-ai
endoflife-ai

Posted on • Originally published at endoflife.ai

Confluence Server End of Life: Two Years Past Support, Three Exploited CVEs, and No Patch Ever Coming

Confluence Server reached end of life on February 15, 2024 — and three actively-exploited, CISA-KEV-listed CVEs (CVE-2021-26084, CVE-2022-26134, CVE-2023-22518) were each fixed only on then-supported branches. Every end-of-life Confluence branch still running carries at least one of them permanently; a 6.x server carries all three. All three are flagged by CISA for known ransomware campaign use. The full wave-by-wave record, version dates, and the honest way out.

The scoreboard: three waves, one pattern

Wave CVE What it is Severity KEV added Fixed only on Left permanently vulnerable
2021 CVE-2021-26084 Unauthenticated OGNL injection → RCE 9.8 (NVD) Nov 3, 2021 6.13, 7.4, 7.11, 7.12, 7.13 branches 6.0–6.12 (4.x/5.x also named affected)
2022 CVE-2022-26134 Unauthenticated OGNL injection → RCE 9.8 (NVD) Jun 2, 2022 7.4 and 7.13–7.18 branches 6.x (every release after 1.3.0 affected)
2023 CVE-2023-22518 Improper authorization → instance reset, attacker-created admin account 9.8 (NVD); 10.0 (Atlassian, revised) Nov 7, 2023 7.19.16, 8.3.4, 8.4.4, 8.5.3, 8.6.1 7.0–7.18 (non-LTS), 6.x, 5.x

What's covered

  • Wave one, 2021: CVE-2021-26084 — and everything before 6.13 is left behind
  • Wave two, 2022: CVE-2022-26134 — same flaw class, same triage, new casualties
  • Wave three, 2023: CVE-2023-22518 — the ransomware wave
  • The scoreboard: three waves, one pattern
  • Why this keeps happening: the lifecycle math
  • What to actually do

Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-confluence-cve-exposure

Top comments (0)