5.3
CVSSv3

CVE-2021-26085

Published: 03/08/2021 Updated: 08/08/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Affected versions of Atlassian Confluence Server allow remote malicious users to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 prior to 7.12.3.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

atlassian confluence server

atlassian confluence data center

Exploits

Atlassian Confluence Server version 751 suffers from a pre-authorization arbitrary file read vulnerability ...

Github Repositories

CVE-2021-26085 Ideas from: githubcom/ColdFusionX/CVE-2021-26085 Modifications from: my burp twittercom/zeroc00I DISCLAIMER: List domains should end by "/" confluence-CVE-2021-26085yaml id: confluence-lfi-fuzz info: name: confluence-lfi-zeroc00I author: zeroc00I severity: high reference: lfi tags: lfi attack: clusterbomb requests: - p

Atlassian Confluence Server 7.5.1 Pre-Authorization Arbitrary File Read vulnerability (CVE-2021-26085)

CVE-2021-26085 Atlassian Confluence Server 751 Pre-Authorization Arbitrary File Read vulnerability POC Vulnerable Endpoints: WEB-INF/webxml WEB-INF/decoratorsxml WEB-INF/classes/seraph-configxml META-INF/maven/comatlassianconfluence/confluence-webapp/pomproperties META-INF/maven/comatlassianconfluence/confluence-webapp/pomxml P

Thanks to @ibra0963 for collecting the tips twittercom/Alra3ees/status/1419058927422017540 The easiest RCE i have found on zerocpter so far:- httpx -l hoststxt -path "/_fragment?_path=_controller=phpcredits&flag=-1" -threads 100 -random-agent -x GET -tech-detect -status-code -follow-redirects -title -mc 200 -match-regex "PHP Credits" ``

confluence-exp

confluence 已定义的功能 暂时支持cve-2021-26085 和 cve-2022-26134, CVE_2023_22515,CVE-2023-22527 过年再看下 支持直接写入冰蝎、哥斯拉内存马 支持不写shell直接获取管理员cookie、添加管理员 支持执行自定义字节码 用法 例: java -jar confluence-expjar -u 127001:8090/ -a godzilla -c cve-2021-26085 -a 可选 behi