ZeroHour
CyberScooppublished ()ingested @shanvav

Amid NSA warning, attacks on Confluence have risen in recent weeks

criticalRansomware exploited in the wildimportance 60CVE-2019-3396

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-3396
Server-Side Template Injection RCE in Atlassian Confluence Server and Data Center

Atlassian Confluence Server and Data Center contain a server-side template injection flaw (CWE-22) in which attacker-supplied template content is processed by the server, enabling path traversal and ultimately remote code execution. An attacker triggers it by submitting crafted template syntax in a request to a vulnerable instance, and can run arbitrary commands or code on the underlying server. Successful compromise could allow data theft, deployment of webshells, or ransomware; CISA notes known ransomware use of this vulnerability. Organizations running self-hosted Confluence Server or Data Center are affected, particularly instances exposed to the internet. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) and EPSS assigns a 99.9% probability of exploitation, placing it in the top percentile.

Do: Apply updates per vendor instructions by upgrading Confluence Server and Data Center to Atlassian's fixed releases, and prioritize internet-facing instances. Until patched, restrict network exposure of Confluence and monitor for signs of compromise such as webshells, unexpected processes, or ransomware activity, since ransomware operators are known to exploit this flaw.

9.8100% KEV ransomware PoC ×4
  • Atlassian Confluence Server and Data Center
largetens of thousands of internet-exposed Confluence Server/Data Center instances, with an installed base plausibly in the hundreds of thousands of servers across…
Full article825 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The NSA warning just got a little more relevant.

nsa confluence
(Logo by Atlassian/image by Scoop News Group)

The National Security Agency’s recent warning about nation-state actors exploiting a vulnerability affecting Confluence wasn’t merely a delayed confirmation of information that the cybersecurity community already had on its radar. It also appears to tip off new exploitation of the vulnerability — hackers have been dramatically stepping up the pace and persistence of their attacks on the popular workplace collaboration software in recent weeks, according to new private sector research obtained by CyberScoop.

The attackers are using a vulnerability that Confluence warned about this spring, according to data from Trend Micro’s TippingPoint technology. And while the NSA issued an advisory last week about the bug, it only says nation-state hackers “have exploited” and “could” exploit the vulnerability, not going so far as to say there has been a recent uptick in attacks.

New information suggests now that the agency had specific reasons to share the guidance this fall: Starting in late September, just weeks before the NSA made its announcement, hackers began exploiting the vulnerability two to three times per day, according to Trend Micro.

The cybersecurity company had seen actors exploit the vulnerability in the months prior, but the attackers then were targeting less frequently, and the uptick in September was particularly notable because it did not appear to abate over a month later, according to the data.

The data also show a brief spike in activity in July.

When reached for comment, NSA press officer Donna Lohr confirmed the “NSA released this advisory based on an uptick in use of this vulnerability,” and emphasized patching the vulnerability.

“NSA would like the community to understand that there is always sound reasoning behind the timing of our advisories; they should be viewed as a call to act,” Lohr said.

The vulnerability, known as CVE-2019-3396, has allowed actors to drop Gandcrab ransomware in the past, according to Alert Logic. It also allows for actors to deploy cryptocurrency mining malware, according to previous Trend Micro research, although it was not immediately clear what the exact targets were in the recent flurry of attacks.

When asked for comment on where targets of the recent spike in exploitation are located, if the same machines were targeted in the spring and the fall, and what threat actors were behind the activity, a Trend Micro spokesperson declined to comment, only noting that the detections were “across its customer base.”

The NSA’s warning on the matter, issued Oct. 30, does not share statistics on exactly when the NSA has seen the vulnerability exploited, how recently it’s been exploited, or the frequency and magnitude of attacks.

But the updated timeline of attacks shows the NSA’s new Cybersecurity Directorate, stood up just one month ago, to be sharing warnings with the public in an unclassified way of threats it is seeing as they are bubbling up — a process which the NSA is working on improving. Just last month the director of the new cybersecurity division said the process of declassifying threat tips and sharing them quickly with the public is a process that needs to be ironed out more to ensure it is giving timely and relevant information to the private sector on nation-state threats.

Beyond giving an eye into whether the NSA is meeting its goals to share relevant information, the resurgence of exploitation of the Confluence vulnerability is a reminder for the broader community that just because companies disclose vulnerabilities in public ways, administrators will not always follow suit by patching.

The NSA recommends patching and disabling the Widget Connector and WebDav plugin2, and provides more information on remediation here.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/nsa-confluence-vulnerability-warning/