CVE-2021-26085
MEDIUM KEV RANSOMWARE NUCLEIAtlassian Confluence Server <7.4.10, >7.5.0-7.12.2 - Info Disclosure
Title source: llmExploitation Summary
CVE-2021-26085 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 28, 2022, with confirmed use in ransomware campaigns. EIP tracks 2 public exploits from researchers including Mayank Deshmukh, ColdFusionX. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a pre-authorization arbitrary file read vulnerability in Atlassian Confluence. It leverages path traversal via crafted HTTP GET requests to access sensitive files like web.xml, seraph-config.xml, and Maven configuration files.
Description
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.
Exploits (2)
This exploit demonstrates a pre-authorization arbitrary file read vulnerability in Atlassian Confluence. It leverages path traversal via crafted HTTP GET requests to access sensitive files like web.xml, seraph-config.xml, and Maven configuration files.
This repository provides functional HTTP request examples demonstrating CVE-2021-26085, an arbitrary file read vulnerability in Atlassian Confluence Server 7.5.1. The PoC includes multiple endpoints for reading sensitive files without authentication.
Nuclei Templates (1)
http.component:"Atlassian Confluence" || http.component:"atlassian confluence"
app="atlassian-confluence"
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N