{"id":6474,"date":"2023-06-22T00:18:57","date_gmt":"2023-06-21T16:18:57","guid":{"rendered":"https:\/\/i007.vip:15443\/wordpress\/?p=6474"},"modified":"2023-06-22T00:18:57","modified_gmt":"2023-06-21T16:18:57","slug":"confluence-security-advisory-2022-06-02","status":"publish","type":"post","link":"https:\/\/i007.cc\/wordpress\/archives\/6474","title":{"rendered":"Confluence Security Advisory 2022-06-02"},"content":{"rendered":"<div class=\"wiki-content\">\n<p><a href=\"https:\/\/confluence.atlassian.com\/doc\/confluence-security-advisory-2022-06-02-1130377146.html\">original text<\/a><\/p>\n<h2><\/h2>\n<h2 id=\"ConfluenceSecurityAdvisory20220602-ConfluenceServerandDataCenter-CVE-2022-26134-Criticalseverityunauthenticatedremotecodeexecutionvulnerability\">Confluence Server and Data Center &#8211; CVE-2022-26134 &#8211; Critical severity\u00a0unauthenticated remote code execution vulnerability<\/h2>\n<div class=\"admonition-block info-block conf-macro output-block\" data-hasbody=\"true\" data-macro-name=\"sp-macrooverride-richtextbody-block\">\n<p><strong>Update:\u00a0<\/strong>This advisory has been updated since its original publication.<\/p>\n<p>Specific updates include:<\/p>\n<p><time class=\"date-past\" datetime=\"2022-06-10\">10 Jun 2022<\/time>\u00a03 PM PDT (Pacific Time, -7 hours)<\/p>\n<ul>\n<li>Updated the\u00a0<strong>Mitigation<\/strong>\u00a0section with steps for Confluence version 6.0.0 and above.<\/li>\n<\/ul>\n<p><time class=\"date-past\" datetime=\"2022-06-03\">03 Jun 2022<\/time>\u00a04 PM PDT (Pacific Time, -7 hours)<\/p>\n<ul>\n<li>Updated to clarify limitation with rolling upgrades in the\u00a0<strong>What You Need to Do<\/strong>\u00a0section.<\/li>\n<\/ul>\n<p><time class=\"date-past\" datetime=\"2022-06-03\">03 Jun 2022<\/time>\u00a010 AM PDT (Pacific Time, -7 hours)<\/p>\n<ul>\n<li>Updated with the fixed versions<\/li>\n<li>Removed interim advice about adding a WAF rule from the\u00a0<strong>What You Need to Do<\/strong>\u00a0section<\/li>\n<\/ul>\n<p><time class=\"date-past\" datetime=\"2022-06-03\">03 Jun 2022<\/time>\u00a08 AM PDT (Pacific Time, -7 hours)<\/p>\n<ul>\n<li>Updating mitigation information to include replacement jar and class files<\/li>\n<\/ul>\n<p><span class=\"date-lozenger-container\"><span class=\"date-node\"><time class=\"date-past\" datetime=\"2022-06-03\">03 Jun 2022<\/time><br \/>\n<\/span><\/span><\/p>\n<ul class=\"ak-ul\">\n<li>Clarifying the affected versions<\/li>\n<li>Adding a WAF rule to the\u00a0<strong>What You Need to Do<\/strong>\u00a0section<\/li>\n<li>Adding estimated timeframe for fixes to be available<\/li>\n<\/ul>\n<\/div>\n<div class=\"table-wrap\">\n<div class=\"table-block\">\n<table class=\"wrapped confluenceTable\">\n<colgroup>\n<col \/>\n<col \/><\/colgroup>\n<tbody>\n<tr>\n<th class=\"confluenceTh\" colspan=\"1\" rowspan=\"1\">Summary<\/th>\n<td class=\"confluenceTd\" colspan=\"1\" rowspan=\"1\">CVE-2022-26134\u00a0&#8211; Critical severity\u00a0unauthenticated remote code execution vulnerability\u00a0in Confluence Server and Data Center<\/td>\n<\/tr>\n<tr>\n<th class=\"confluenceTh\" colspan=\"1\" rowspan=\"1\">Advisory Release Date<\/th>\n<td class=\"confluenceTd\" colspan=\"1\" rowspan=\"1\">\n<div class=\"content-wrapper\">\n<p><time class=\"date-past\" datetime=\"2022-06-02\">02 Jun 2022<\/time>\u00a01 PM PDT (Pacific Time, -7 hours)<\/p>\n<\/div>\n<\/td>\n<\/tr>\n<tr>\n<th class=\"confluenceTh\" colspan=\"1\" rowspan=\"1\">Affected Products<\/th>\n<td class=\"confluenceTd\" colspan=\"1\" rowspan=\"1\">\n<ul class=\"ak-ul\">\n<li>Confluence\n<ul class=\"ak-ul\">\n<li>Confluence Server<\/li>\n<li>Confluence Data Center<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<th class=\"confluenceTh\" colspan=\"1\" rowspan=\"1\">Affected Versions<\/th>\n<td class=\"confluenceTd\" colspan=\"1\" rowspan=\"1\">\n<ul>\n<li>All\u00a0<strong>supported<\/strong>\u00a0versions of Confluence Server and Data Center are affected.<\/li>\n<li>Confluence Server and Data Center versions after 1.3.0 are affected.<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<th class=\"confluenceTh\" colspan=\"1\" rowspan=\"1\">Fixed Versions<\/th>\n<td class=\"confluenceTd\" colspan=\"1\" rowspan=\"1\">\n<ul class=\"ak-ul\">\n<li>7.4.17<\/li>\n<li>7.13.7<\/li>\n<li>7.14.3<\/li>\n<li>7.15.2<\/li>\n<li>7.16.4<\/li>\n<li>7.17.4<\/li>\n<li>7.18.1<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<th class=\"confluenceTh\" colspan=\"1\" rowspan=\"1\">CVE ID(s)<\/th>\n<td class=\"confluenceTd\" colspan=\"1\" rowspan=\"1\">CVE-2022-26134<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<h3 id=\"ConfluenceSecurityAdvisory20220602-Severity\">Severity<\/h3>\n<p>Atlassian rates the severity level of this vulnerability as\u00a0<strong>critical<\/strong>, according to the scale published in\u00a0<a class=\"external-link\" title=\"https:\/\/www.atlassian.com\/security\/security-severity-levels\" href=\"https:\/\/www.atlassian.com\/security\/security-severity-levels\" rel=\"nofollow\">our Atlassian severity levels<\/a>.\u00a0The scale\u00a0allows us to rank the severity as critical, high, moderate or low.<\/p>\n<p>This is our assessment and you should evaluate its applicability to your own IT environment.<\/p>\n<h3 id=\"ConfluenceSecurityAdvisory20220602-Description\">Description<\/h3>\n<p>Atlassian has been made aware of current active exploitation of a critical severity unauthenticated remote code execution vulnerability in Confluence Data Center and Server. The OGNL injection vulnerability allows an unauthenticated user to execute arbitrary code on a Confluence Server or Data Center instance.<\/p>\n<p>All versions of Confluence Server and Data Center prior to the fixed versions listed above are affected by this vulnerability.<\/p>\n<p>This issue can be tracked here:<\/p>\n<p><span class=\"jira-issue resolved\" data-jira-key=\"CONFSERVER-79016\"><a class=\"jira-issue-key\" href=\"https:\/\/jira.atlassian.com\/browse\/CONFSERVER-79016\"><img decoding=\"async\" class=\"icon\" src=\"https:\/\/jira.atlassian.com\/secure\/viewavatar?size=xsmall&#038;avatarId=98192&#038;avatarType=issuetype\" \/>CONFSERVER-79016<\/a>\u00a0&#8211;\u00a0<span class=\"summary\">Remote code execution via OGNL injection in Confluence Server &#038; Data Center &#8211; CVE-2022-26134<\/span>\u00a0<span class=\"aui-lozenge aui-lozenge-subtle             aui-lozenge-success\n     jira-macro-single-issue-export-pdf\">PUBLISHED<\/span><\/span><\/p>\n<div class=\"admonition-block info-block conf-macro output-block\" data-hasbody=\"true\" data-macro-name=\"sp-macrooverride-richtextbody-block\">\n<p>Atlassian Cloud sites are protected<\/p>\n<p>If your Confluence site is accessed via an\u00a0<a class=\"external-link\" href=\"http:\/\/atlassian.net\/\" rel=\"nofollow\">atlassian.net<\/a>\u00a0domain, it\u00a0is hosted by Atlassian and is not vulnerable. Our investigations have not found any evidence of exploitation of Atlassian Cloud.<\/p>\n<\/div>\n<h3 id=\"ConfluenceSecurityAdvisory20220602-Fix\">Fix<\/h3>\n<p>We have taken the following steps to address this\u00a0issue:<\/p>\n<ul class=\"ak-ul\">\n<li>Released\u00a0versions 7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4 and 7.18.1\u00a0which contain a fix for this issue.<\/li>\n<\/ul>\n<p><strong>What You Need to Do<\/strong><\/p>\n<p>Atlassian recommends that you upgrade to the latest Long Term Support release. For a full description of the latest version, see the\u00a0<a class=\"conf-macro output-inline\" href=\"https:\/\/confluence.atlassian.com\/doc\/confluence-release-notes-327.html\" data-macro-name=\"sp-plaintextbody-link\" data-hasbody=\"true\">Confluence Server and Data Center Release Notes<\/a>. You can download the latest version\u00a0from the\u00a0<a class=\"external-link\" href=\"https:\/\/www.atlassian.com\/software\/confluence\/download-archives\" rel=\"nofollow\">download centre<\/a>.<\/p>\n<p>Note: If you run Confluence in a cluster, you will not be able to upgrade to the fixed versions without downtime, also known as a rolling upgrade. Follow the steps in\u00a0<a href=\"https:\/\/confluence.atlassian.com\/doc\/upgrading-confluence-data-center-1507377.html\" rel=\"nofollow\">Upgrading Confluence Data Center<\/a>.<\/p>\n<h4 id=\"ConfluenceSecurityAdvisory20220602-Mitigation\"><strong>Mitigation<\/strong><\/h4>\n<p>If you are unable to upgrade Confluence immediately, then as a\u00a0<strong>temporary<\/strong>\u00a0workaround, you can mitigate the CVE-2022-26134 issue by updating the following files for the specific version of the product.<\/p>\n<h4 id=\"ConfluenceSecurityAdvisory20220602-ForConfluence7.15.0-7.18.0\">\nFor Confluence 7.15.0 &#8211; 7.18.0<\/h4>\n<p>If you run Confluence in a cluster, you will need to repeat this process on each node. You don&#8217;t need to shut down the whole cluster to apply this mitigation.<\/p>\n<ol class=\"ak-ol\">\n<li>Shut down Confluence.<\/li>\n<li>Download the following 1 file to the Confluence server:\n<ul class=\"ak-ol\">\n<li><a class=\"external-link\" href=\"https:\/\/packages.atlassian.com\/maven-internal\/opensymphony\/xwork\/1.0.3-atlassian-10\/xwork-1.0.3-atlassian-10.jar\" rel=\"nofollow\">xwork-1.0.3-atlassian-10.jar<\/a><\/li>\n<\/ul>\n<\/li>\n<li><strong>Delete<\/strong>\u00a0(or\u00a0<strong>move<\/strong>\u00a0the following\u00a0<span class=\"fabric-editor-annotation\">JAR outside\u00a0<\/span>of the Confluence install directory):\n<div class=\"code-block conf-macro output-block\" data-hasbody=\"true\" data-macro-name=\"sp-macrooverride-plaintextbody-block\">\n<pre class=\" language-none\"><code class=\" language-none\"><confluence-install>\/confluence\/WEB-INF\/lib\/xwork-1.0.3-atlassian-8.jar<\/code><\/pre>\n<\/div>\n<p><img decoding=\"async\" class=\"emoticon emoticon-warning\" src=\"https:\/\/confluence.atlassian.com\/s\/-3ku14d\/8703\/1gj57ki\/_\/images\/icons\/emoticons\/warning.svg\" alt=\"(warning)\" data-emoticon-name=\"warning\" \/>\u00a0Do not leave a copy of this old JAR in the directory.<\/li>\n<li>Copy the downloaded\u00a0<strong>xwork-1.0.3-atlassian-10.jar<\/strong>\u00a0into\u00a0<code><confluence-install>\/confluence\/WEB-INF\/lib\/<br \/>\n<\/code><\/li>\n<li>Check the permissions and ownership on the new\u00a0<strong>xwork-1.0.3-atlassian-10.jar<\/strong>\u00a0file matches the existing files in the same directory.<\/li>\n<li>Start Confluence.<\/li>\n<\/ol>\n<p><strong>Remember<\/strong>, If you run Confluence in a cluster, make sure you apply the above update on all of your nodes.<\/p>\n<h4 id=\"ConfluenceSecurityAdvisory20220602-ForConfluence6.0.0-Confluence7.14.2\">For Confluence 6.0.0 &#8211; Confluence 7.14.2<\/h4>\n<p>If you run Confluence in a cluster, you will need to repeat this process on each node. You don&#8217;t need to shut down the whole cluster to apply this mitigation.<\/p>\n<ol class=\"ak-ol\">\n<li>Shut down Confluence.<\/li>\n<li>Download the following 3 files to the Confluence server:\n<ul class=\"ak-ol\">\n<li><a class=\"external-link\" href=\"https:\/\/packages.atlassian.com\/maven-internal\/opensymphony\/xwork\/1.0.3-atlassian-10\/xwork-1.0.3-atlassian-10.jar\" rel=\"nofollow\">xwork-1.0.3-atlassian-10.jar<\/a><\/li>\n<li><a class=\"external-link\" href=\"https:\/\/packages.atlassian.com\/maven-internal\/opensymphony\/webwork\/2.1.5-atlassian-4\/webwork-2.1.5-atlassian-4.jar\" rel=\"nofollow\">webwork-2.1.5-atlassian-4.jar<\/a><\/li>\n<li><a class=\"conf-macro output-inline\" href=\"https:\/\/confluence.atlassian.com\/doc\/files\/1130377146\/1137639562\/3\/1654274890463\/CachedConfigurationProvider.class\" data-macro-name=\"sp-nobody-link\" data-hasbody=\"false\">CachedConfigurationProvider.class<\/a><\/li>\n<\/ul>\n<\/li>\n<li><strong>Delete<\/strong>\u00a0(or\u00a0<strong>move<\/strong>\u00a0the following JARs outside of the Confluence install directory):\n<div class=\"code-block conf-macro output-block\" data-hasbody=\"true\" data-macro-name=\"sp-macrooverride-plaintextbody-block\">\n<pre class=\" language-none\"><code class=\" language-none\"><confluence-install>\/confluence\/WEB-INF\/lib\/xwork-1.0.3.6.jar\r\n<confluence-install>\/confluence\/WEB-INF\/lib\/webwork-2.1.5-atlassian-3.jar<\/code><\/pre>\n<\/div>\n<p><img decoding=\"async\" class=\"emoticon emoticon-warning\" src=\"https:\/\/confluence.atlassian.com\/s\/-3ku14d\/8703\/1gj57ki\/_\/images\/icons\/emoticons\/warning.svg\" alt=\"(warning)\" data-emoticon-name=\"warning\" \/>\u00a0Do not leave a copy of the old JARs in the directory.<\/li>\n<li>Copy the downloaded\u00a0<strong>xwork-1.0.3-atlassian-10.jar<\/strong>\u00a0into\u00a0<code><confluence-install>\/confluence\/WEB-INF\/lib\/<br \/>\n<\/code><\/li>\n<li>Copy the downloaded\u00a0<strong>webwork-2.1.5-atlassian-4.jar<\/strong>\u00a0into\u00a0<code><confluence-install>\/confluence\/WEB-INF\/lib\/<br \/>\n<\/code><\/li>\n<li>Check the permissions and ownership on\u00a0<strong>both new files<\/strong>\u00a0matches the existing files in the same directory.<\/li>\n<li>Change to directory\u00a0<code><confluence-install>\/confluence\/WEB-INF\/classes\/com\/atlassian\/confluence\/setup<br \/>\n<\/code><\/p>\n<ol class=\"ak-ol\">\n<li>Create a new directory called\u00a0<code>webwork<\/code><\/li>\n<li>Copy\u00a0<strong>CachedConfigurationProvider.class<\/strong>\u00a0into\u00a0<code><confluence-install>\/confluence\/WEB-INF\/classes\/com\/atlassian\/confluence\/setup\/webwork<\/code><\/li>\n<li>Ensure the permissions and ownership are correct for:\n<div class=\"code-block conf-macro output-block\" data-hasbody=\"true\" data-macro-name=\"sp-macrooverride-plaintextbody-block\">\n<pre class=\" language-none\"><code class=\" language-none\"><confluence-install>\/confluence\/WEB-INF\/classes\/com\/atlassian\/confluence\/setup\/webwork<\/code><\/pre>\n<\/div>\n<div class=\"code-block conf-macro output-block\" data-hasbody=\"true\" data-macro-name=\"sp-macrooverride-plaintextbody-block\">\n<pre class=\" language-none\"><code class=\" language-none\"><confluence-install>\/confluence\/WEB-INF\/classes\/com\/atlassian\/confluence\/setup\/webwork\/CachedConfigurationProvider.class<\/code><\/pre>\n<\/div>\n<\/li>\n<\/ol>\n<\/li>\n<li>Start Confluence.<\/li>\n<\/ol>\n<p>Remember, If you run Confluence in a cluster, make sure you apply the above update on all of your nodes.<\/p>\n<p><strong>Note<\/strong>: Confluence\u00a0<a class=\"conf-macro output-inline\" href=\"https:\/\/confluence.atlassian.com\/support\/atlassian-support-end-of-life-policy-201851003.html\" data-macro-name=\"sp-plaintextbody-link\" data-hasbody=\"true\">End Of Life<\/a>\u00a0versions are not fully tested with the workaround.<\/p>\n<p>We\u00a0<strong>strongly recommend\u00a0<\/strong>upgrading to a fixed version of Confluence as there are several other security fixes included in the fixed versions of Confluence.<\/p>\n<h3 id=\"ConfluenceSecurityAdvisory20220602-Acknowledgments\">Acknowledgments<\/h3>\n<p>We would like to thank\u00a0<a class=\"external-link\" href=\"https:\/\/www.volexity.com\/blog\/2022\/06\/02\/zero-day-exploitation-of-atlassian-confluence\/\" rel=\"nofollow\">Volexity<\/a>\u00a0for identifying this vulnerability.<\/p>\n<h3 id=\"ConfluenceSecurityAdvisory20220602-Support\">Support<\/h3>\n<p>If you did not receive an email for this advisory and wish to receive such emails in the future, please go to\u00a0<a class=\"external-link\" title=\"https:\/\/my.atlassian.com\/email\" href=\"https:\/\/my.atlassian.com\/email\" rel=\"nofollow\">https:\/\/my.atlassian.com\/email<\/a>\u00a0and subscribe to\u00a0Alerts emails.<\/p>\n<p>If you have questions or concerns regarding this advisory, please raise a support request at\u00a0<a class=\"external-link\" title=\"https:\/\/support.atlassian.com\/\" href=\"https:\/\/support.atlassian.com\/\" rel=\"nofollow\">https:\/\/support.atlassian.com\/<\/a>.<\/p>\n<h3 id=\"ConfluenceSecurityAdvisory20220602-References\">References<\/h3>\n<div class=\"table-wrap\">\n<div class=\"table-block\">\n<table class=\"wrapped confluenceTable\">\n<colgroup>\n<col \/>\n<col \/><\/colgroup>\n<tbody>\n<tr>\n<td class=\"confluenceTd\" colspan=\"1\" rowspan=\"1\"><a class=\"external-link\" href=\"https:\/\/www.atlassian.com\/trust\/security\/bug-fix-policy\" rel=\"nofollow\">Security Bug fix Policy<\/a><\/td>\n<td class=\"confluenceTd\" colspan=\"1\" rowspan=\"1\">As per our new policy critical security bug fixes will be back ported in accordance with\u00a0<a class=\"external-link\" title=\"https:\/\/www.atlassian.com\/trust\/security\/bug-fix-policy\" href=\"https:\/\/www.atlassian.com\/trust\/security\/bug-fix-policy\" rel=\"nofollow\">https:\/\/www.atlassian.com\/trust\/security\/bug-fix-policy<\/a>.\u00a0 We will release new maintenance releases for the versions covered by the policy instead of binary patches.<\/p>\n<p><strong>Binary patches are no longer released.\u00a0<\/strong><\/td>\n<\/tr>\n<tr>\n<td class=\"confluenceTd\" colspan=\"1\" rowspan=\"1\"><a class=\"external-link\" title=\"https:\/\/www.atlassian.com\/security\/security-severity-levels\" href=\"https:\/\/www.atlassian.com\/security\/security-severity-levels\" rel=\"nofollow\">Severity Levels for security issues<\/a><\/td>\n<td class=\"confluenceTd\" colspan=\"1\" rowspan=\"1\">Atlassian security advisories include a severity level and a CVE identifier. This severity level is based on our self-calculated CVSS score for each specific vulnerability. CVSS is an industry standard vulnerability metric. You can also learn more about CVSS at\u00a0<a class=\"external-link\" title=\"https:\/\/www.first.org\/cvss\/user-guide\" href=\"https:\/\/www.first.org\/cvss\/user-guide\" rel=\"nofollow\">FIRST.org<\/a>.<\/td>\n<\/tr>\n<tr>\n<td class=\"confluenceTd\" colspan=\"1\" rowspan=\"1\"><a class=\"conf-macro output-inline\" href=\"https:\/\/confluence.atlassian.com\/support\/atlassian-support-end-of-life-policy-201851003.html\" data-macro-name=\"sp-plaintextbody-link\" data-hasbody=\"true\">End of Life Policy<\/a><\/td>\n<td class=\"confluenceTd\" colspan=\"1\" rowspan=\"1\">\u00a0Our end of life policy varies for different products. Please refer to our EOL Policy for details.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"content-page-last-modified-date\">Last modified on Jun 10, 2022<\/div>\n","protected":false},"excerpt":{"rendered":"<p>original text Conflu<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[24],"tags":[121],"class_list":["post-6474","post","type-post","status-publish","format-standard","hentry","category-value_docs","tag-05-"],"_links":{"self":[{"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/posts\/6474","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/comments?post=6474"}],"version-history":[{"count":0,"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/posts\/6474\/revisions"}],"wp:attachment":[{"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/media?parent=6474"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/categories?post=6474"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/tags?post=6474"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}