google / tsunami-security-scanner-plugins

This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.
Apache License 2.0
860 stars 178 forks source link

PRP: Atlassian Confluence RCE (CVE-2023-22527) #377

Open secureness opened 5 months ago

secureness commented 5 months ago

Hi, this is a request for writing a tsunami plugin for this CVE-2023-22527 which is a pre-auth RCE and I think we can implement it as a tsunami scanner plugin. Ref: https://blog.projectdiscovery.io/atlassian-confluence-ssti-remote-code-execution/

tooryx commented 5 months ago

Thank you @secureness for willing to contribute. You still have several other issue that are in the queue, so I will put this one on hold for now.

~tooryx

jimmy-ly00 commented 2 months ago

@tooryx @secureness is anyone working on this? I have made a module on Netattacker in the past so will be a quick win: https://github.com/OWASP/Nettacker/pull/797