QID 150368

Date Published: 2021-09-27

QID 150368: Atlassian Confluence Server Webwork OGNL Injection RCE Vulnerability (CVE-2021-26084)

An OGNL injection vulnerability CVE-2021-26084 exists in Confluence Server that could allow an authenticated user, and in some instances unauthenticated user, to execute arbitrary code on a Confluence Server or Data Center instance.

Affected versions:
Confluence Server prior to version 6.13.23
Confluence Server version 6.14.0 to 7.4.11
Confluence Server version 7.5.0 to 7.11.6
Confluence Server version 7.12.0 to 7.12.5

QID Detection Logic (Unauthenticated) :
This QID sends a specially-crafted HTTP POST request to "pages/createpage-entervariables.action" and/or "pages/doenterpagevariables.action" with OGNL payload to check if the target is vulnerable.

Successful exploitation of the vulnerability will allow remote attacker to execute arbitrary code on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to latest Atlassian Confluence Server or later versions to remediate this vulnerability.
    Vendor References

    CVEs related to QID 150368

    Software Advisories
    Advisory ID Software Component Link
    CONFSERVER-67940 URL Logo jira.atlassian.com/browse/CONFSERVER-67940