DEV Community

yutianle
yutianle

Posted on

Confluence exposure: 1.8 million fingerprint matches depend on which fingerprint you use

Confluence exposure: 1.8 million fingerprint matches depend on which fingerprint you use

The wiki that holds the architecture

A Confluence instance usually contains the material an attacker wants before touching a server: network diagrams, credential rotation procedures, cloud account structure, escalation paths and onboarding guides. It is also, in most organisations, reachable from the corporate network and often from the internet for partner access.
Measuring how much of it is exposed turns out to depend heavily on which query is used, and the difference is large enough to change the conclusion.

What was queried

Three queries against ZoomEye on 2026-09-26 (UTC), Python SDK, sub_type=all, page size one:

  • app="Atlassian Confluence": 1,847,430
  • app="Confluence": 179,807
  • title="Confluence": 1,208,692

Why the two fingerprints differ by a factor of ten

The longer application string returns roughly ten times the matches of the shorter one. In this dataset, the fully qualified name is the productive fingerprint, and the short form is not a subset that behaves predictably. Recording both is the honest approach: they are different observations of overlapping populations.
The title query lands between the two at 1,208,692. Title matches include login pages, 404 pages served by a configured application, and any page whose title mentions the product. That is a broader and noisier set than a curated fingerprint, but it is also the set that catches builds the signature does not recognise.
For an operator the lesson is procedural. When a finding depends on a single fingerprint, the finding inherits the coverage of that fingerprint. Two queries with an explicit note about which one drives the decision make the conclusion reproducible next quarter.

Practical implications

  1. Use the qualified application fingerprint as the primary measure and keep the title query as a secondary estimate. Record both with the collection time, so a future comparison is not confused by a signature update.
  2. For the assets in scope, the questions worth asking are the ones Atlassian's own security guidance frames: is anonymous access disabled, are public links audited and expired, is the instance version current, and are administrative accounts separated from content authors.
  3. Monitor for change. A Confluence instance that becomes reachable is often a new deployment or a migration, and both produce a short window during which configuration is at its most permissive.

Limitations

These are matched asset counts. They do not prove that an instance is unauthenticated, that content is readable, or that a specific version with a specific advisory is installed. Atlassian Cloud instances and self-managed instances behave differently and are not separated by these queries. Counts change with signature updates and with the ordinary life cycle of internet-facing services.

References

Top comments (0)