
Confluence Server および Data Center - CVE-2022-26134 - 重要度 Critical の認証不要のリモートコード実行脆弱性 PoC
Confluence ServerおよびData Center - CVE-2022-26134 - 重大な深刻度の認証されていないリモートコード実行脆弱性 PoC

Atlassianは、Atlassianの深刻度レベルに基づき、この脆弱性の深刻度をCriticalと評価しています。上記の修正バージョンより前のすべてのConfluence ServerおよびData Centerのバージョンが影響を受けます。
リリースバージョン7.4.17、7.13.7、7.14.3、7.15.2、7.16.4、7.17.4、7.18.1にこの問題の修正が含まれています。
git clone https://github.com/shamo0/CVE-2022-26134.git
cd CVE-2022-26134
python3 exploit.py https://target.com CMD
https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html
https://github.com/Nwqda/CVE-2022-26134
https://jira.atlassian.com/browse/CONFSERVER-79016
https://bugalert.org/content/notices/2022-06-02-confluence.html