CVE-2021-26085:Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

splash
Back

Description Preview

CVE-2021-26085 is a critical security vulnerability affecting Atlassian Confluence Server that allows remote attackers to view restricted resources through a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. This vulnerability enables unauthenticated attackers to read arbitrary files from the affected Confluence Server installation, potentially exposing sensitive information. The vulnerability affects Confluence Server versions before 7.4.10, and versions 7.5.0 through 7.12.2.

Overview

This vulnerability (CWE-425: Direct Request) allows attackers to bypass intended access restrictions and access files that should be protected. By exploiting the vulnerability in the /s/ endpoint, an attacker can read arbitrary files from the server's file system without requiring authentication. This could lead to exposure of sensitive configuration files, credentials, or other confidential information stored on the server. The vulnerability is particularly severe because it can be exploited pre-authentication, meaning an attacker doesn't need valid credentials to exploit it.

Remediation

Organizations running affected versions of Atlassian Confluence Server should immediately upgrade to a patched version:

  • For versions before 7.4.10, upgrade to version 7.4.10 or later
  • For versions 7.5.0 through 7.12.2, upgrade to version 7.12.3 or later

If immediate patching is not possible, consider implementing network-level controls to restrict access to the Confluence Server, particularly to the vulnerable /s/ endpoint. Monitor for suspicious access attempts to this endpoint, especially those that might be attempting to access files outside the normal web content directories.

References

  1. Atlassian Jira Issue: https://jira.atlassian.com/browse/CONFSERVER-67893
  2. Exploit Details: http://packetstormsecurity.com/files/164401/Atlassian-Confluence-Server-7.5.1-Arbitrary-File-Read.html
  3. CWE-425: Direct Request - https://cwe.mitre.org/data/definitions/425.html

Early Warning

Armis Early Warning customers received an advanced alert on this vulnerability.

Armis Alert Date
Oct 7, 2021
CISA KEV Date
Mar 28, 2022
172days early
Learn More

Industry ExposureMost to least
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.

  1. Manufacturing
    Manufacturing
  2. Professional, Scientific, & Technical Services
    Professional, Scientific, & Technical Services
  3. Public Administration
    Public Administration
  4. Wholesale Trade
    Wholesale Trade
  5. Accommodation & Food Services
    Accommodation & Food Services
  6. Administrative, Support, Waste Management & Remediation Services
    Administrative, Support, Waste Management & Remediation Services
  7. Agriculture, Forestry Fishing & Hunting
    Agriculture, Forestry Fishing & Hunting
  8. Arts, Entertainment & Recreation
    Arts, Entertainment & Recreation
  9. Construction
    Construction
  10. Educational Services
    Educational Services
  11. Finance and Insurance
    Finance and Insurance
  12. Health Care & Social Assistance
    Health Care & Social Assistance
  13. Information
    Information
  14. Management of Companies & Enterprises
    Management of Companies & Enterprises
  15. Mining
    Mining
  16. Other Services (except Public Administration)
    Other Services (except Public Administration)
  17. Real Estate Rental & Leasing
    Real Estate Rental & Leasing
  18. Retail Trade
    Retail Trade
  19. Transportation & Warehousing
    Transportation & Warehousing
  20. Utilities
    Utilities

Focus on What Matters

  1. See Everything.
  2. Identify True Risk.
  3. Proactively Mitigate Threats.

Let's talk!

background