← voltar
CVE-2021-26084

CVE-2021-26084

CVSS 9.8 CRITICALEPSS 100.0%● KEVCWE-917
Em resumo

Uma falha de segurança no Confluence permite que atacantes executem código malicioso no servidor sem precisar fazer login. O problema ocorre porque o software não valida corretamente a entrada do usuário ao processar expressões, abrindo caminho para execução de comandos.

Detalhe técnico

Uma vulnerabilidade de injeção OGNL (CWE-917) no Confluence Server e Data Center permite execução remota de código sem autenticação através de validação inadequada de entrada. O vetor de ataque é pela rede e não requer credenciais; as versões afetadas falham em sanitizar expressões fornecidas pelo usuário antes de processá-las no motor OGNL, permitindo execução arbitrária de comandos.

Resumo gerado e traduzido por IA a partir da descrição oficial.
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
PoCs públicas encontradas37
githubgithub.com/hev0x/CVE-2021-26084_Confluence316githubgithub.com/0xf4n9x/CVE-2021-2608472githubgithub.com/alt3kx/CVE-2021-26084_PoC53githubgithub.com/dinhbaouit/CVE-2021-2608453githubgithub.com/1ZRR4H/CVE-2021-2608430githubgithub.com/crowsec-edtech/CVE-2021-2608421githubgithub.com/Vulnmachines/Confluence_CVE-2021-260848githubgithub.com/taythebot/CVE-2021-260848githubgithub.com/lleavesl/CVE-2021-260847githubgithub.com/JKme/CVE-2021-260845githubgithub.com/BBD-YZZ/Confluence-RCE5githubgithub.com/orangmuda/CVE-2021-260844githubgithub.com/BeRserKerSec/CVE-2021-26084-Nuclei-template3githubgithub.com/ludy-dev/CVE-2021-26084_PoC3githubgithub.com/Loneyers/CVE-2021-260843githubgithub.com/toowoxx/docker-confluence-patched2githubgithub.com/nizar0x1f/CVE-2021-26084-patch-1githubgithub.com/TheclaMcentire/CVE-2021-26084_Confluence1githubgithub.com/Jun-5heng/CVE-2021-260841githubgithub.com/prettyrecon/CVE-2021-26084_Confluence1githubgithub.com/GlennPegden2/cve-2021-26084-confluence1githubgithub.com/nahcusira/CVE-2021-260841githubgithub.com/bcdannyboy/CVE-2021-26084_GoPOC1githubgithub.com/CrackerCat/CVE-2021-260840githubgithub.com/Xc1Ym/cve_2021_260840githubgithub.com/wolf1892/confluence-rce-poc0githubgithub.com/attacker-codeninja/CVE-2021-260840githubgithub.com/Osyanina/westone-CVE-2021-26084-scanner0githubgithub.com/b1gw00d/CVE-2021-260840githubgithub.com/smallpiggy/cve-2021-26084-confluence0githubgithub.com/maskerTUI/CVE-2021-260840githubgithub.com/p0nymc1/CVE-2021-260840githubgithub.com/wdjcy/CVE-2021-260840githubgithub.com/quesodipesto/conflucheck0githubgithub.com/30579096/Confluence-CVE-2021-260840cve_referencepacketstormsecurity.com/files/167449/Atlassian-Confluence-Namespace-OGNL-Injection.htmlnão verificadoexploitdbwww.exploit-db.com/exploits/50243não verificado
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →