Jenkins project attacked through Atlassian Confluence vulnerability

Опубликовано: 02 Октябрь 2024
на канале: CSI digital
145
6

Jenkins project attacked through Atlassian Confluence vulnerability

Jenkins, a leading open source automation server, announced on Saturday that its deprecated Confluence service was successfully attacked through the Confluence CVE-2021-26084 exploit -- something that US Cybercom warned of in a notice last week.

In a statement, Jenkins documentation officer Mark Waite explained that the affected server was taken offline and the team is investigating the impact of the issue.

"At this time we have no reason to believe that any Jenkins releases, plugins, or source code have been affected. Thus far in our investigation, we have learned that the Confluence CVE-2021-26084 exploit was used to install what we believe was a Monero miner in the container running the service," Waite wrote.

"From there an attacker would not be able to access much of our other infrastructure. Confluence did integrate with our integrated identity system which also powers Jira, Artifactory, and numerous other services."

Waite added that there is no indication that any developer credentials were taken during the attack but that they "cannot assert otherwise and are therefore assuming the worst."

Jenkins said that until it re-establishes a "chain of trust with our developer community," it will be preventing releases. Every account password has been reset and the Jenkins infrastructure team has permanently disabled the Confluence service. The team has also rotated privileged credentials and taken measures to reduce the scope of access across their infrastructure.

"We are working closely with our colleagues at the Linux Foundation and the Continuous Delivery Foundation to ensure that infrastructure which is not directly managed by the Jenkins project is also scrutinized," Waite noted.

"In October 2019 we made the Confluence server read-only effectively deprecating it for day-to-day use within the project. At that time, we began migrating documentation and changelogs from the wiki to GitHub repositories. That migration has been ongoing, with hundreds of plugins and many other documentation pages moved from the wiki to GitHub repositories."

The notice comes after multiple IT leaders took to social media to confirm that CVE-2021-26084 was indeed being exploited.

"Affected servers should be patched immediately. The vulnerability is exploitable by unauthenticated users regardless of configuration," Atlassian added to their previous notice.