ZeroHour
The Recordpublished ()ingested

Atlassian warns that Confluence zero

criticalExploit / PoC exploited in the wildimportance 60CVE-2022-26134

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-26134
Unauthenticated OGNL Injection RCE in Atlassian Confluence Server/Data Center

Atlassian Confluence Server and Data Center contain an unauthenticated remote code execution flaw caused by improper neutralization of expression-language (OGNL) input (CWE-917): an attacker with network access to the application can submit a crafted request that is evaluated as an expression and executed by the server. Successful exploitation lets a remote, unauthenticated attacker run arbitrary code with the privileges of the Confluence process, without any credentials. All organizations running self-managed Confluence Server or Data Center are affected, particularly instances exposed to the internet; Confluence Cloud is not listed among the affected products. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-06-02 with ransomware use marked as known, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile). CVSS has not yet been scored in this data, but the KEV listing and known ransomware use make unpatched, internet-facing instances a top-priority patching target.

Do: Immediately upgrade to the patched Confluence release specified in Atlassian's 2022-06-02 security advisory, and until patched follow the CISA required action to block all internet traffic to and from affected instances. Because in-the-wild exploitation and ransomware use are confirmed, also hunt for compromise indicators on both patched and unpatched hosts, such as webshells, unexpected child processes of the Confluence service, and unusual outbound connections.

9.8100% KEV ransomware PoC ×2
  • Atlassian Confluence Server
  • Atlassian Confluence Data Center
largetens of thousands of internet-exposed instances (public scan counts of roughly 60,000-90,000 Confluence Server/Data Center hosts around the June 2022…
Full article605 words · extracted from therecord.media · click to collapse

Update (2:01 pm EST): Atlassian has released a patch for the bug and said it has notified all potentially vulnerable customers of the fix.

Atlassian has warned its customers that hackers are exploiting a zero-day vulnerability in all supported versions of Confluence Server and Data Center.

A spokesperson for the Australia-based software firm told The Record that the bug – tagged as CVE-2022-26134 – does not yet have a patch. 

“We have contacted all potentially vulnerable customers directly to alert them of this vulnerability. Atlassian Engineering teams are actively working on a patch, and we will update our security advisory with an estimate for completion as soon as possible,” the spokesperson said. 

Atlassian was tight-lipped about the specifics of the critical unauthenticated remote code execution vulnerability in an effort to protect users while a patch is created. In its advisory on the issue, the company said a security fix will be “available for customer download within 24 hours (estimated time, by EOD June 3 PDT).”

The company suggested users restrict access to Confluence Server and Data Center instances from the internet or disable instances. For those unable to take these measures, Atlassian suggested implementing a Web Application Firewall rule which blocks URLs containing ${. 

Atlassian said the issue was discovered by security firm Volexity, which released its own blog about the vulnerability. 

We found a remote, pre-auth 0day being exploited in Confluence Server in the wild. In the blog post, we break down our forensic analysis steps and provide the IOCs that we currently can. If you have this product then you need to deal with this immediately as no patch is available https://t.co/uuofF7mvyb

— Andrew Case (@attrc) June 2, 2022

Volexity security researchers Andrew Case, Sean Koessel, Steven Adair and Thomas Lancaster said they conducted an incident response investigation over Memorial Day weekend that involved suspicious activity on two internet-facing web servers belonging to one of its customers that were running Atlassian Confluence Server software.

“After a thorough review of the collected data, Volexity was able to determine the server compromise stemmed from an attacker launching an exploit to achieve remote code execution. Volexity was subsequently able to recreate that exploit and identify a zero-day vulnerability impacting fully up-to-date versions of Confluence Server,” the company explained. 

They contacted Atlassian on May 31, and noted that it resembles “previous vulnerabilities that have also been exploited in order to gain remote code execution.”

Volexity said these brands of vulnerabilities are particularly dangerous because they allow attackers to execute commands and “gain full control of a vulnerable system without credentials as long as web requests can be made to the Confluence Server system.”

We believe this exploit is in the hands of multiple CN threat actors and since publishing our blog have learned of multiple other compromised organizations beyond our initial work and visibility. This is become more widespread.

— Steven Adair (@stevenadair) June 2, 2022

The attacker discovered by Volexity exploited the vulnerability and deployed a copy of BEHINDER, a popular web server implant that they said “provides very powerful capabilities to attackers, including memory-only webshells and built-in support for interaction with Meterpreter and Cobalt Strike.”

The Cybersecurity and Infrastructure Security Agency (CISA) released its own warning about the bug and immediately added it to its catalog of known exploited vulnerabilities

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/atlassian-warns-that-confluence-zero-day-is-being-exploited-by-hackers