An exploit for CVE 2021-26084 that is widely distributed allows an unauthenticated attacker to execute remote code using the OGNL language, which is a simplified version of Java’s expression language. The first patch for the vulnerability was released on August 25, 2021, and the CVE associated with the patched vulnerability received a CVSS score of 9.8/10 due to the difficulty of developing a weaponized exploit. Despite this, a reliable exploit and walkthrough were publicly released on Github on Tuesday, August 31, 2021, Internet-wide scanning for the vulnerability was observed, and several hundred vulnerability reports of unpatched Confluence instances were received via the Bugcrowd platform.
Bugcrowd believes that CVE 2021-26084 is also being exploited by malicious attackers, based on the widespread deployment of Confluence Server, the ease of access to and reliability of an exploit, and the groundswell of scanning and exploitation of this vulnerability, and that organizations should prioritize identifying Confluence Server instances in their environment and commence patching IMMEDIATELY.
An OGNL injection vulnerability exists in affected versions of Confluence Server and Data Center, allowing an authenticated user, and in some cases an unauthenticated user, to execute arbitrary code on a Confluence Server or Data Center instance. If “Allow people to sign up to create their account” is enabled, a non-administrator user or an unauthenticated user can access the vulnerable endpoints. To see if this is enabled, navigate to COG > User Management > User Signup Options. Before version 6.13.23, before version 7.4.11, before version 7.5.0 before 7.11.6, and before version 7.12.0 before 7.12.5 are the affected versions.
Vendor advisory: https://jira.atlassian.com/browse/CONFSERVER-67940
Vendor patch: https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html
First public writeup and exploit: https://github.com/httpvoid/writeups/blob/main/Confluence-RCE.md
Widespread scanning: https://twitter.com/haxor31337/status/1432731786719551489
News:https://therecord.media/confluence-enterprise-servers-targeted-with-recent-vulnerability/
Every minute that goes by, your unknown vulnerabilities leave you more exposed to cyber attacks.