PT-2022-3814 · Atlassian · Confluence+1
CVE-2022-26138
·
Published
2022-07-20
·
Updated
2024-11-05
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Atlassian Questions For Confluence app versions 2.7.34 through 3.0.2
Description
The Atlassian Questions For Confluence app creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. The estimated number of potentially affected devices worldwide is over 8000 servers. There have been reports of active exploitation of this issue in the wild.
Recommendations
For versions 2.7.34, 2.7.35, and 3.0.2, update to a newer version that contains a fix for this issue, such as version 2.7.38 or 3.0.5, to prevent the creation of the vulnerable user account and remove it if it already exists.
As a temporary workaround, consider deleting the disabledsystemuser account to minimize the risk of exploitation.
Restrict access to the confluence-users group to minimize the risk of exploitation until a patch is applied.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Questions For Confluence
Confluence