CVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Proxy)


Description

Detects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.

Query · sigma

selection_method:
  cs-method: POST
selection_uris:
  cs-uri|contains:
  - /json/setup-restore-local.action
  - /json/setup-restore-progress.action
  - /json/setup-restore.action
  - /server-info.action
  - /setup/setupadministrator.action
selection_status:
  sc-status:
  - 200
  - 302
  - 405
condition: all of selection_*

Known false positives

  • Vulnerability scanners
Raw source CVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Proxy) · Sigma
Esc
Published by SigmaHQ/sigma ↗, licensed under Detection Rule License 1.1 ↗. Reproduced here unmodified.
title: CVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Proxy)
id: 27d2cdde-9778-490e-91ec-9bd0be6e8cc6
related:
    - id: a902d249-9b9c-4dc4-8fd0-fbe528ef965c
      type: similar
status: test
description: |
    Detects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.
references:
    - https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html
    - https://www.huntress.com/blog/confluence-to-cerber-exploitation-of-cve-2023-22518-for-ransomware-deployment
    - https://github.com/ForceFledgling/CVE-2023-22518
author: Andreas Braathen (mnemonic.io)
date: 2023-11-14
tags:
    - attack.initial-access
    - attack.t1190
    - cve.2023-22518
    - detection.emerging-threats
logsource:
    category: proxy
detection:
    selection_method:
        cs-method: 'POST'
    selection_uris:
        cs-uri|contains:
          # Exploitable endpoints
            - '/json/setup-restore-local.action'
            - '/json/setup-restore-progress.action'
            - '/json/setup-restore.action'
            - '/server-info.action'
            - '/setup/setupadministrator.action'
    selection_status:
        # Response code may be indicative of exploitation success, but is not always the case
        sc-status:
            - 200
            - 302
            - 405
    condition: all of selection_*
falsepositives:
    - Vulnerability scanners
level: medium

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.