QID 150523
Date Published: 2022-06-07
QID 150523: Atlassian Confluence Server and Data Center OGNL Injection Remote Code Execution (RCE) Vulnerability (CVE-2022-26134)
Confluence is a team collaboration software. Written in Java and mainly used in corporate environments, it is developed and marketed by Atlassian.
An OGNL injection vulnerability CVE-2022-26134 exists in Confluence Server that allows unauthenticated user, to execute arbitrary code on a Confluence Server or Data Center instance.
Affected versions:
Confluence Server prior to version 1.3.0
Confluence Server prior to version 7.4.17
Confluence Server prior to version 7.13.7
Confluence Server prior to version 7.14.3
Confluence Server prior to version 7.15.2
Confluence Server prior to version 7.16.4
Confluence Server prior to version 7.17.4
Confluence Server prior to version 7.18.1
QID Detection Logic (Unauthenticated) :
This QID sends a specially-crafted HTTP request with OGNL payload to add a Custom HTTP Response Header and based on the response determines if the target is vulnerable.
Successful exploitation of the vulnerability will allow remote attacker to execute arbitrary code on the target system.
- Atlassian Confluence Security Advisory -
confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html
CVEs related to QID 150523
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Atlassian Confluence Security Advisory |
|