CVE-2024-21683 is a high-severity remote code execution vulnerability affecting Atlassian Confluence Data Center and Server. The issue was introduced in Confluence version 5.2. Successful exploitation allows an authenticated attacker to execute arbitrary code on the vulnerable Confluence instance without requiring user interaction. Available information identifies the flaw as affecting Confluence Data Center and Server, but does not provide sufficient technical detail about the vulnerable component, function, or root cause to assign a reliable CWE or describe the precise exploitation mechanism.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
Repository purpose: proof-of-concept exploit for CVE-2024-21683 against Atlassian Confluence Server/Data Center, leveraging the Code Macro plugin configuration feature to upload a malicious JavaScript "language" file. Structure: - CVE-2024-21683.py: main exploit script (Python). Implements a full authenticated exploitation flow: (1) login to /dologin.action with admin credentials, (2) request /admin/plugins/newcode/configure.action and parse the atlassian-token meta tag using BeautifulSoup, (3) POST to /doauthenticate.action with atl_token and admin password, then (4) upload a user-specified JS file to /admin/plugins/newcode/addlanguage.action as multipart form data. - exploit.js: example payload that uses Java interop (ProcessBuilder) to spawn calc.exe, demonstrating server-side command execution. - README.md: describes the vulnerability, prerequisites (authenticated admin with permission to add a new macro language), and provides a usage example. Notable implementation details: - Uses requests.Session() to maintain cookies. - Disables TLS verification (verify=False) and supports an intercepting proxy (default http://127.0.0.1:8083). - The -n/--name argument is parsed but not actually used in the upload request (newLanguageName is hardcoded to "test" in upload_evil_js_file), suggesting minor PoC quality issues. Overall capability: authenticated remote exploitation via administrative Confluence endpoints to upload a malicious script file intended to trigger RCE in the vulnerable component.
This repository contains a single Metasploit module targeting Atlassian Confluence servers vulnerable to CVE-2024-21683. The exploit requires valid administrator credentials and targets a flaw in the Rhino script engine parser, which allows arbitrary code execution via uploaded text files. The module authenticates to the Confluence instance, verifies administrator privileges, determines the underlying OS, and uploads a payload to trigger remote code execution. The exploit supports both Linux and Windows platforms and affects a wide range of Confluence versions (all prior to 7.17 and many up to 8.9.0). The main endpoints involved are the login and admin console pages. The payload enables execution of arbitrary OS commands as the Confluence service user. The code is written in Ruby and is designed to be used within the Metasploit framework.
This repository provides an exploit for CVE-2024-21683, a remote code execution vulnerability in Atlassian Confluence's 'newcode' plugin. The main exploit script (CVE-2024-21683.py) is written in Python and automates the process of authenticating as an administrator, retrieving a CSRF token, and uploading a malicious JavaScript file (exploit.js) to the vulnerable endpoint. The JavaScript payload leverages Java interop to execute an arbitrary system command (calc.exe), demonstrating code execution on the server. The exploit requires valid administrator credentials and targets the web interface of Confluence, making it a network-based, authenticated attack. The repository is structured with a main Python exploit script, a simple JavaScript payload, and a README with usage instructions. Multiple HTTP endpoints related to authentication and plugin management are targeted in the attack flow.
This repository provides a working exploit for CVE-2024-21683, a remote code execution vulnerability in Atlassian Confluence's 'newcode' plugin. The exploit consists of a Python script (poc.py) that automates the attack process: it logs into the Confluence instance using provided admin credentials, retrieves an anti-CSRF token, authenticates, and uploads a malicious JavaScript file (exploit.js) via the plugin's language upload functionality. The JavaScript payload leverages Java's ProcessBuilder to execute arbitrary system commands on the server (demonstrated with 'calc.exe'). The README provides usage instructions and example parameters. The exploit requires network access to the target Confluence server and valid admin credentials. The endpoints targeted are specific to the Confluence plugin's administrative actions. The repository is structured with a main exploit script (poc.py), a payload file (exploit.js), and a README for guidance.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in Atlassian Confluence, rejected by CVE.org but with evidence of exploitation and available Metasploit module.
A vulnerability identified only by CVE ID in a Confluence-related dataset filename; no further details are provided in the content.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.