漏洞描述 AtlassianConfluence是Atlassian公司出品的专业wiki程序。攻击者可利用漏洞在未经身份验证的情况下,远程构造OGNL表达式进行注入,在ConfluenceServer或Data Center上执行任意代码。
相关漏洞推荐 POC CVE-2017-5983: JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE) Atlassian Jira Software Data Center And Server 需授权 路径遍历漏洞 CVE-2019-3396: Atlassian Confluence Path Traversal Atlassian Confluence /json/setup-restore.action 文件上传漏洞(CVE-2023-22518) POC CVE-2015-8399: Atlassian Confluence <5.8.17 - Information Disclosure POC CVE-2017-9506: Atlassian Jira IconURIServlet - Cross-Site Scripting/Server-Side Request Forgery POC CVE-2018-20824: Atlassian Jira WallboardServlet <7.13.1 - Cross-Site Scripting POC CVE-2018-5230: Atlassian Jira Confluence - Cross-Site Scripting POC CVE-2019-11580: Atlassian Crowd and Crowd Data Center - Unauthenticated Remote Code Execution POC CVE-2019-11581: Atlassian Jira Server-Side Template Injection POC CVE-2019-3396: Atlassian Confluence Server - Path Traversal POC CVE-2019-3398: Atlassian Confluence Download Attachments - Remote Code Execution POC CVE-2019-3401: Atlassian Jira <7.13.3/8.0.0-8.1.1 - Incorrect Authorization