PT-2022-3814 · Atlassian · Confluence+1

CVE-2022-26138

·

Published

2022-07-20

·

Updated

2024-11-05

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Atlassian Questions For Confluence app versions 2.7.34 through 3.0.2
Description The Atlassian Questions For Confluence app creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. The estimated number of potentially affected devices worldwide is over 8000 servers. There have been reports of active exploitation of this issue in the wild.
Recommendations For versions 2.7.34, 2.7.35, and 3.0.2, update to a newer version that contains a fix for this issue, such as version 2.7.38 or 3.0.5, to prevent the creation of the vulnerable user account and remove it if it already exists. As a temporary workaround, consider deleting the disabledsystemuser account to minimize the risk of exploitation. Restrict access to the confluence-users group to minimize the risk of exploitation until a patch is applied.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04612
CVE-2022-26138

Affected Products

Questions For Confluence
Confluence