Confluence Data Center — Authentication Bypass via Setup Endpoint
Summary. Atlassian Confluence Data Center and Server fail to validate setup-token rotation in the /setup endpoint, allowing unauthenticated attackers to forge an admin session and execute arbitrary setup actions, including SMTP reconfiguration and user-import.
Exploit chain. Endpoint enumeration → token-state inspection via timing oracle → admin session forge → persistent SMTP relay for credential phishing.
In-the-wild signal. Two customer SIEMs logged probe traffic from AS4134 backbone ranges 36h before public disclosure.
indicator-pattern: [file:hashes.'SHA-256' = 'a31f...c902'] malware-classification: trojan.linux.confluence-bypass first-seen: 2024-10-21T03:14:00Z