Confluence Data Center and Confluence Server Vulnerabilities
Confluence Data Center and Server Privilege Escalation: networkWeb ServerNoneversion:11
The following analytic identifies potential exploitation attempts on a known vulnerability in Atlassian Confluence, specifically targeting the /setup/*.action* URL pattern. It leverages web logs within the Splunk 'Web' Data Model, filtering for successful accesses (HTTP status 200) to these endpoints. This activity is significant as it suggests attackers might be exploiting a privilege escalation flaw in Confluence. If confirmed malicious, it could result in unauthorized access or account creation with escalated privileges, leading to potential data breaches or further exploitation within the environment.
Windows Metasploit Confluence Plugin Execution: endpointEndpointNoneversion:2
Detects the malicious java plugin execution used by metasploit for Atlassian Confluence exploitation.
This usually leads to the download of meterpreter giving the actor full control over the Confluence server.
Windows Unusual File Creation in Confluence Directory: endpointEndpointNoneversion:3
The following analytic detects executable file formats being created within the Confluence main directory.
This can be indicative of exploitation of the Confluence web services to stage malware.
This won't catch adversaries who modify the output location outside the Confluence directory when exploiting.
Confluence Pre-Auth RCE via OGNL Injection CVE-2023-22527: networkWeb ApplicationNoneversion:9
The following analytic identifies attempts to exploit a critical template injection vulnerability (CVE-2023-22527) in outdated Confluence Data Center and Server versions. It detects POST requests to the "/template/aui/text-inline.vm" endpoint with HTTP status codes 200 or 202, indicating potential OGNL injection attacks. This activity is significant as it allows unauthenticated attackers to execute arbitrary code remotely. If confirmed malicious, attackers could gain full control over the affected Confluence instance, leading to data breaches, system compromise, and further network infiltration. Immediate patching is essential to mitigate this threat.
Confluence Unauthenticated Remote Code Execution CVE-2022-26134: networkWeb ServerNoneversion:10
The following analytic detects attempts to exploit CVE-2022-26134, an unauthenticated remote code execution vulnerability in Confluence. It leverages the Web datamodel to analyze network and CIM-compliant web logs, identifying suspicious URL patterns and parameters indicative of exploitation attempts. This activity is significant as it allows attackers to execute arbitrary code on the Confluence server without authentication, potentially leading to full system compromise. If confirmed malicious, this could result in unauthorized access, data exfiltration, and further lateral movement within the network. Immediate investigation and remediation are crucial to prevent extensive damage.