Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

When too much access is not enough: a story about Confluence and tokens

Summary

Quarkslab red team story: after compromising a Confluence host and its database but lacking app credentials, they study the Confluence database structure and API token generation mechanism.
Published
Collected

original ↗

Related coverage

back