Atlassian Confluence SSTI Injection

Discussion in 'News Aggregator' started by Packet Storm, 27 Jan 2024.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits an SSTI injection in Atlassian Confluence servers. A specially crafted HTTP request uses the injection to evaluate an OGNL expression resulting in OS command execution. Versions 8.5.0 through 8.5.3 and 8.0 to 8.4 are known to be vulnerable.

    Continue reading...
     

Share This Page

Loading...