Sploitus

Exploit for Expression Language Injection in Atlassian Confluence Data Center CVE-2019-3396 CVE-2022-26134

githubexploit · 2022-06-07

Exploit Code

README38 lines
## https://sploitus.com/exploit?id=469B060E-C585-599E-A0D1-AD5D186F70FD
# Confluence Pre-Auth Remote Code Execution via OGNL Injection (CVE-2022-26134) in Ruby 


Confluence is a web-based corporate wiki developed by Australian software company Atlassian.

On June 02, 2022 Atlassian released a security advisory for their Confluence Server and Data Center applications, highlighting a critical severity unauthenticated remote code execution vulnerability. The OGNL injection vulnerability allows an unauthenticated user to execute arbitrary code on a Confluence Server or Data Center instance.

References:

- 
- 
- 

## Vulnerable Environment

Execute following command to start a Confluence Server 7.13.6:

```
docker-compose up -d
```

After the environment starts, visit ``http://your-ip:8090`` and you will see the installation guide, select "Trial installation", then you will be asked to fill in the license key. You should apply for a Confluence Server test certificate from Atlassian.

Following [this guide](https://github.com/vulhub/vulhub/tree/master/confluence/CVE-2019-3396) to complete the installation.

On the database configuration page, fill in the form with database address `db`, database name `confluence`, username `postgres`, password `postgres`.


## Exploit 

Note: Exploit is still under development , any pull request ideas are welcomed 

![Habib0x](https://user-images.githubusercontent.com/24976957/172489563-3d3611b3-7d86-4d01-bd6b-e4c4fd90d744.png)



https://user-images.githubusercontent.com/24976957/172490114-2b81b6f1-9c4d-4542-9d8d-e4d7b4a82d9d.mov