Finding Confluence servers with Rumble

(updated ), by Pearce Barry
icon
Rumble, Inc. is now runZero!

Rumble Network Discovery is now runZero!

The U.S. Cyber Command recently reported “mass exploitation” of a code execution vulnerability in Atlassian’s popular Confluence software (CVE-2021-26084). This vulnerability has a CVSS Base score of 9.8 (considered “critical”), requires no authentication for exploitation, and affects many on-prem versions of the product (Atlassian says that Confluence Cloud customers are not affected). Public reports of exploitation are surfacing, including a Confluence instance of the Jenkins project compromised for cryptomining purposes.

Atlassian has provided fixed versions that on-prem Confluence admins should upgrade to as soon as possible, as well as mitigations for those who cannot upgrade immediately. As an aside, there have been some interesting events around the leaking of a private exploit PoC during disclosure with a vulnerable party.

Finding Confluence servers with Rumble

From the Services Inventory, use the following pre-built query to locate systems in your network that are running Confluence:

_asset.protocol:http AND has:http.head.xConfluenceRequestTime
Find Confluence servers

As always, any prebuilt queries we create are available from our Queries Library. Check out the library for other useful inventory queries.

Get runZero for free

Find Confluence servers on your network in minutes with runZero.

Get started
Rumble Screenshot

Similar Content

February 15, 2023

Finding OpenSSH servers

The OpenSSH team surfaced a security issue earlier this month that specifically affects OpenSSH server version 9.1p1 (a.k.a. version 9.1). This version contains a memory double-free vulnerability (tracked as CVE-2023-25136) that can be reached pre-authentication by a remote …

Read More

February 8, 2023

Finding VMware ESXi assets

This Rapid Response post covers ESXiArgs, a new strain of ransomware that is targeting VMware ESXi servers. Learn how you can find potentially affected servers on your network.

February 3, 2023

Finding Lexmark printer assets

Printer manufacturer Lexmark recently published details on a vulnerability that affects over 100 of their printer models. Learn how runZero can help you find potentially affected assets.