27 ms·
Zero-Day Exploitation of Atlassian Confluence
- dijit 4y agoPart of me believes that the lack of workaround or patch and the vagueness of the warning, coupled with their cloud product being safe is a very happy accident. Given how much they’re pushing the hosted offering.
- richbell 4y agoBoth Atlassian and CISA are recommending either disconnecting servers from the internet or shutting them off entirely. I don't like the sounds of this. https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html https://confluence.atlassian.com/doc/confluence-security-adv... https://twitter.com/USCERT_gov/status/1532511428451631108?t=LcNUFm3cOUbYM6en-0eC_Q&s=19 https://twitter.com/USCERT_gov/status/1532511428451631108?t=...
- bombcar 4y agoWhich is very strange, they usually have at least a workaround or URL to block.
- throwaway939343 4y agoSorry what now? You cannot simply block the current attackers control addresses (they actually do give you these) or domains. First they could be either VPN users or "residential proxies" aka legitimate people with a botnet on their pc. Second the attacker - or anyone else who now knows it exists - can just change URLs or IPs. They can change the exploit signature so anti-virus and IDS systems can't trivially see it. The ONLY correct solution here is to bring the servers offline until there is a patched version to upgrade to. Anything else would be a terrible idea. _sometimes_ there is only one config setting that's affected, or some other often lesser-used feature that can be disabled. But it highly depends on the method used.
- eps 4y agoGP meant that oftentimes exploits use a specific entry point on the public surface and blocking access to it acts as a stop-gap measure.
- yardstick 4y agoThey’ve suggested blocking ${ in the request
- Icingdeath 4y agoUsing nginx in front of my local confluence server (not listening on the internet) and used the following: location ~\* \$\{. { deny all; } but this only helps if this vulnerability is triggered using the request uri otherwise it's useless
- bombcar 4y agoAnyone know how you'd quote it for Apache rewrite? RewriteEngine On RewriteCond %{REQUEST_URI} ^.*\${.*$ RewriteRule ^/(.*) https://google.com [R=302,L] seems to work ...
- justin_oaks 4y agoThe security advisory from Atlassian says blocking ${ "may reduce your risk". That's a far cry from being a fix.
- technion 4y agoI really worry about these sort of claims. I'm seeing pushback from people about shutting servers down because it's insisted "a WAF is protecting us now", and that's based on a "may reduce risk".
- richbell 4y agoSame issue with log4shell. "Why are you bugging us? We already applied <mitigation posted 2 weeks ago that has since been disproven>."
- tyingq 4y agoI would worry about just using that blocking pattern. They mention OGNL injection and ${ is just one pattern you can go after. There's also #{, %{, #var, and more.
- justin_oaks 4y agoThere are now manual steps for mitigating the vulnerability. See https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html https://confluence.atlassian.com/doc/confluence-security-adv... It is strange that they didn't have mitigation steps earlier, but I'm guessing Atlassian announced this immediately since it was already being exploited.
- bombcar 4y agohttps://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html https://confluence.atlassian.com/doc/confluence-security-adv... is updated with a workaround that you can apply manually now. Posting this high here so it can be seen.
- deleted 4y ago[deleted]
- bombcar 4y agoAnd now the same link has the released update versions. And more details: https://jira.atlassian.com/browse/CONFSERVER-79000 https://jira.atlassian.com/browse/CONFSERVER-79000
- tyingq 4y agoPart of the fix is a patched version of xwork 1.0.3, originally released in 2005, which has had several CVEs past 1.0.3. Yikes.
- yabones 4y agoHacked together a quick and dirty shell script to install on my boxes in a repeatable way... Hope this helps others that find themselves in this situation. https://gist.github.com/noahbailey/0260efa836b4ea67163cbfeef579b93a https://gist.github.com/noahbailey/0260efa836b4ea67163cbfeef...
- yabones 4y agoThis is a great case for why proxy pre-auth is so important. Doesn't matter how buggy and riddled with worms your app server is if nobody can get to it without a valid token. Sure, it introduces plenty of other problems, but it does really help with this. At the end of the day, you shouldn't be able to execute anything until you're authenticated.
- harmon 4y agoAgreed, if not a proxy then put your services behind a VPN or a bastion host when possible.
- pm90 4y agoYup. Really easy to set this up with the IDP's available today too.
- RulerOf 4y agoIn the IdP/SP/SAML sense of it, I'm really used to that level of validation actually hitting the application and being processed through an authentication subsystem, rather than being done at the webserver level. Possibly just some nginx features I'm not familiar with, or are there whole apps out there that serve to be nothing other than an authentication layer inside of a webserver? Are they popular?
- tyingq 4y agoHTTP Redirecting out to an idp and it posting back to the application with a SAML assertion is pretty common, if that's what you mean. Lots of people do that with things like O365, the AWS Web Console, etc.
- RulerOf 4y agoOf course. Just asking how is the web router aware of whether or not the redirect is necessary if you're not hitting the application to validate login state.
- 4y ago
- albert_e 4y ago> Atlassian Cloud sites are protected > If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable. Our investigations have not found any evidence of exploitation of Atlassian Cloud Must be a relief for Atlassian after the recent long outage that only impacted cloud instances.
- bombcar 4y agoWhich is strange because it means either something catches the exploit or it’s particular to the stand-alone code, as cloud is mostly (but not entirely) DataCenter.
- rst 4y agoThey also might have a hot fix (or temporary feature disable) that they've applied in Cloud, but not yet packaged for distribution.
- rozenmd 4y agoTheir cloud and on-prem offerings diverged quite a while ago, so it makes sense
- dx034 4y agoMaybe just a WAF rule like Cloudflare rolled out. But then they should've stated that since there is a chance cloud instances were breached.
- meibo 4y agoTheir communication around the recent downtime was pretty terrible, so I wouldn't be surprised if they just didn't mention this and took it as a fact. Then again, they may have confirmed it via logs.
- deleted 4y ago[deleted]
- smiddereens 4y ago
- deleted 4y ago[deleted]
- tyingq 4y agoFrom: https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html https://confluence.atlassian.com/doc/confluence-security-adv... "If you are unable to take the above actions implementing a WAF (Web Application Firewall) rule which blocks URLs containing ${ may reduce your risk." Smells like log4j issues? Edit: Ah, template injection, see below.
- technion 4y agoIt's a common pattern in Java injection vulnerabilities. You can see an example here: https://portswigger.net/research/server-side-template-injection https://portswigger.net/research/server-side-template-inject...
- eastdakota 4y agoWe’ve applied protection for all Cloudflare customers, including those on our free plan: https://blog.cloudflare.com/cloudflare-customers-are-protected-from-the-atlassian-confluence-cve-2022-26134/ https://blog.cloudflare.com/cloudflare-customers-are-protect...
- jacquesm 4y agoIt's funny how over the years I've come to both love and hate (insert Michael Kiwanuka joke here) Cloudflare more and more. The number of use cases where there is substantial benefit is now much larger than I ever foresaw when you guys launched, at the same time Cloudflare now has so much power that any mistakes or changes in direction that bother me have far more impact than before. Best of luck in navigating this, it's a very fine line. (For the record, Cloudflare, Stripe and a limited set of other companies are in my opinion some of the few that 'made it big' and that didn't turn into disasters or abusers of their position, in contrast with Google, Microsoft, Apple, Facebook and many many others)
- dogecoinbase 4y agoThis is the paradox of centralization, isn't it -- we can't run our own email servers anymore, because we can't send email to the major providers. We can't run our websites without engaging with CAs because HTTPS is a requirement. We won't be able to run our own platforms, because without the protection of a well-resourced middleman like Cloudflare to stay up 24/7 mitigating our issues, the overcomplexified and permanently insecure state of modern software would be intolerable.
- jacquesm 4y agoIndeed it is. And I think this is the reason the centralization/decentralization pendulum is there in the first place. But in the past the return (decentralization) of that pendulum was driven by major advances in technology, this time around that won't be happening and absent another driver we may be more or less stuck.
- dgb23 4y ago
- killjoywashere 4y agoThis lands the day after di2e.net shutters their IL-2 instance? Coincidence?
- photon-torpedo 4y agoGreat timing. Here in the UK it's a four-day weekend. Can imagine that many affected will see this too late...
- jacquesm 4y agoNot monitoring the components in your setup for security announcements is a fairly basic error. Someone should be watching these. Otherwise every Christmas would be a hackfest.
- SnowHill9902 4y agoThat’s where diversity hiring shines.
- richbell 4y ago> Otherwise every Christmas would be a hackfest. It probably is. I raised the alarm for log4shell internally on December 9th, and then then it was being actively exploited. I know people at other companies who hadn't heard about it, or didn't think it was worth doing anything about, as recently as April.
- AdrianLudwig 4y agoA quick update -- we've just notified Confluence Server and Data Center customers that we expect security fixes for supported versions of Confluence will begin to be available for customer download within 24 hours. We will continue to update our advisory (https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html https://confluence.atlassian.com/doc/confluence-security-adv...) at least every 24 hours as additional details become available - including a download link to the software updates as soon as they are available.
- bombcar 4y agoI wish these emergency patches could be made available as a marketplace app to install rather than a complete code update; as the latter takes much longer to implement.
- bombcar 4y agoHey! This temp fix isn't a bad one, it's easy to apply and restart. https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html https://confluence.atlassian.com/doc/confluence-security-adv...
- mkleczek 4y agoNot long after log4shell yet another example of why JEP 411 (removal of SecurityManager) is a very questionable decision. Running applications under SecurityManager would have prevented a lot of these vulnerabilities (or rather - their severity would be much lower).
- planb 4y agoWhy? You still get full access to everything the app can see - all Confluence content. To prevent access to the rest of the system, there are better ways now (Containers). YMMV, but SecurityManager was never really usable in most real word use cases.
- dx034 4y agoTo be fair, with most stuff running as VMs, a confluence server will usually not run anything else. So root doesn't really change much here I guess.
- Chyzwar 4y agoVM might have access to more cloud resources via bad AIM policies. Getting access to root even in container can be just as bad.
- mkleczek 4y ago> You still get full access to everything the app can see - all Confluence content. No (with proper policy in place). That's the whole point of SecurityManager. Even if you can execute code - it is sandboxed and has limited (or none at all) permissions.
- bzzzt 4y agoWhy is removing a legacy component which is effectively ignored and unusable by most modern applications an issue? SecurityManager is very fine-grained so you have to spec out every file access by your application (including those of third party code you may or may not know about). Most server side Java deployments run without it so you're better off making sure the permissions of the server process are correct than customising the Java policy.
- smokey_circles 4y ago1) why would you not use a vpn or other gateway between confluence server and the internet? 2) presumably for the same reason they ran confluence as root: no idea what they're doing (forgivable) or lazy (unforgivable)
- bombcar 4y agoAlso a surprisingly large number of publicly available documentation is hosted on internet-open confluence pages.
- perlgeek 4y agoHave you looked at the security of VPN products in the past 2ish years? Basically every one of the big ones had several really dumb and easily exploitable RCEs. It doesn't really help you to use a security product in front of your vulnerable product when the security product turns out to be roughly equally vulnerable.
- brtkdotse 4y agoSidetrack, what's a good collaborative wiki? I've tried a bunch but always found Confluence much more polished than other offerings.
- jraph 4y agoI'm working at XWiki SAS [1], which provides hosting, support and customization for XWiki [2], an open source extensible wiki you can use for collaboration in a team (among other things). We are seeing many clients coming from Confluence because of the recent price raise and so we have tools to migrate from Confluence. They seem happy. There are ways to customize XWiki to fulfill the specific need of each team if the wiki is a model that suits you. There are a lot of extensions available and you can program in the wiki itself to adapt it if standard XWiki lack some specific feature you'd need. I don't know Confluence though, so I cannot say how more or less polished XWiki is compared to Confluence. Anyway, don't hesitate to reach the XWiki community (there's a public forum and a public matrix channel, come say hello!) or XWiki SAS if you have questions or concerns, they'll be happy to answer and you can see whether XWiki would be a good fit for you :-) [1] https://xwiki.com/ https://xwiki.com/ [2] https://xwiki.org/ https://xwiki.org/
- tommoor 4y agoWe've seen a _lot_ of folks coming across from Confluence to Outline since Atlassian stopped offering on-premise licenses. We have a cloud, self-hosted community, and on-premise offerings. https://getoutline.com https://getoutline.com
- dobin 4y agoWhen I evaluated some last year, my favourites have been Bookstack and Wiki.js. Both are open source.
- micw 4y agoHave a look at https://www.bookstackapp.com/ https://www.bookstackapp.com/. It's open source, very polished and also useable for non-techies.
- quickthrower2 4y ago
- ninjin-carh 4y agoI haven't seen why exploits have been released but this doesn't feel like responsible disclosure to me https://en.m.wikipedia.org/wiki/Coordinated_vulnerability_disclosure https://en.m.wikipedia.org/wiki/Coordinated_vulnerability_di...
- mngnt 4y agoFrom what I understand, the vulnerability had already been exploited in the wild. Voxelity discovered it thanks to it being exploited at a client's system.
- 0daystock 4y agoAwesome. Maybe finally mailbox.org (and lots of other providers) will apprehend that using the same password for Jira helpdesk and my email inbox is a terrible idea. Then again, what privacy can one really expect from email anyway?
- DeathArrow 4y agoTLDR. But can I delete the tasks from the damn thing without logging?
- bombcar 4y agohttps://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html https://confluence.atlassian.com/doc/confluence-security-adv... is updated with a workaround that you can apply manually now.
- bombcar 4y agoAnd now the same link has the released update versions.
- AdrianLudwig 4y agoThe security advisory has been updated with new information regarding a fix for for Confluence Data Center and Server products. Please see the advisory for more information and updated instructions. https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html https://confluence.atlassian.com/doc/confluence-security-adv...