
سيعلم هذا السكربت المستخدم ما إذا كان مثيل Confluence معرضًا للثغرات، لكنه لن يتابع خطوات الاستغلال.
إخلاء مسؤولية
هذا السكريبت مخصص للأغراض التعليمية والاختبارية فقط. استخدمه بمسؤولية وتأكد من أن لديك إذنًا لاختبار مثيل Confluence المستهدف. الاختبار غير المصرح به غير قانوني وغير أخلاقي.
يتحقق هذا السكريبت مما إذا كان مثيل Confluence معرضًا للثغرة الأمنية CVE-2023-22515، وهي ثغرة حرجة من نوع التحكم المكسور في الوصول (Broken Access Control) تؤثر على Atlassian Confluence Data Center وServer الإصدارات 8.0.0 وما فوق. لا يستغل السكريبت الثغرة؛ بل يتحقق فقط من الإصدار وتكوين وضع الإعداد.
requestspackagingيمكنك تثبيت المكتبات المطلوبة باستخدام pip:
pip install requests packaging
Clone the repository or download the script file.
Run the script in your Python environment:
python confluence_vulnerability_check.py
Input the URL of the Confluence instance when prompted (e.g., http://example.com).
The script will check the Confluence version and determine if the instance is vulnerable to CVE-2023-22515.
Output
The script will output the Confluence version and inform you whether the instance is vulnerable based on the version and setup mode check. Example output:
Enter the URL of the Confluence instance (e.g., http://example.com): http://example.com
Confluence version detected: 7.19.22
The Confluence instance is not vulnerable to CVE-2023-22515.
Contributing
Contributions are welcome! Please open an issue or submit a pull request.