We found CVE-2024-4367 in confluence version 8.5.10 and did not find an official way to deal with this vulnerability? How to make an effective fix?
Vulnerability Overview
In Confluence version 8.5.10, PDF.JS is referenced for loading and parsing PDF files. However, a previous vulnerability, CVE-2024-4367, exists in the PDF.JS plugin, affecting versions <= 4.1.392. It was discovered through testing that the version of PDF.JS used in Confluence 8.5.10 is also affected by this vulnerability.
An attacker can exploit this vulnerability by uploading a malicious PDF file. When the victim previews or opens this file, the malicious JavaScript code is automatically executed, leading to remote code execution (RCE) or theft of the victim's cookies. This could further allow the attacker to take control of the victim's system, steal sensitive information, bypass authentication mechanisms, and directly access the victim's account.
Reference links for CVE-2024-4367:
Following a solution from your official forum, modifying specific database table fields to disable the preview function is practically unfeasible.
I hope you can assist me in resolving this issue.
Vulnerability Steps
Attack Command
The following Python script is used to construct the malicious PDF file(I use this command to steal users' cookies):
Python:
Capture Victim's Cookies The attacker receives the victim's cookies on the server.
Use Cookies The attacker can use the stolen cookies to log into the victim's account without entering a username and password, leading to identity theft and sensitive data leakage. Since the page can be shared, any user can access the PDF, allowing us to steal cookies from any user.
Remote Code Execution (RCE) By further exploiting this vulnerability, the attacker can achieve remote code execution, leading to more severe system damage.
Conclusion
This vulnerability can lead to serious consequences, including remote code execution, data theft, and identity theft.
How can this issue be addressed effectively?