Confluence Web Installer Scanner

Targets the Confluence setup endpoint to check if installation pages are publicly accessible, enabling attackers to view sensitive configuration details.

Short Info


Level

High

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

17 days 15 hours

Scan only one

URL

Toolbox

Confluence is a team collaboration software developed by Atlassian, widely used by organizations for knowledge management, project documentation, and team communication. It serves as a central hub where teams create, share, and collaborate on content, integrating with tools like Jira and Slack. Administrators deploy Confluence on-premises or in cloud environments, managing user permissions and workflows. Its extensibility through plugins makes it a versatile platform for enterprise productivity, supporting everything from meeting notes to technical documentation.

The vulnerability involves the exposure of Confluence's installation page after initial setup. This arises from a misconfiguration where the setup wizard remains accessible, allowing unauthorized users to view or interact with configuration settings. Typically, this occurs when administrators fail to disable the installation endpoint post-deployment, leaving sensitive options like database credentials or admin account setup exposed.

Technically, the scanner checks the /setup/setupadministrator.action or similar endpoints that are part of Confluence's installation process. If these pages are accessible without authentication, an attacker can retrieve information about the instance's configuration state. The vulnerability is not tied to a specific CVE but is a common security oversight in Confluence deployments, often due to incomplete hardening steps.

If exploited, an attacker could gather sensitive details about the Confluence environment, such as database type, version, or network configuration. This information can be used to plan further attacks, like SQL injection or privilege escalation. In worst-case scenarios, the exposed setup page might allow reinstallation or modification of settings, leading to full compromise of the Confluence instance and potential data breaches.

Get started to protecting your digital assets