CVE-2022-26138
Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.
Required action
Apply updates per vendor instructions.
CISA notes
https://confluence.atlassian.com/doc/questions-for-confluence-security-advisory-2022-07-20-1142446709.html; https://nvd.nist.gov/vuln/detail/CVE-2022-26138
Description
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAffected Products
| Vendor | Product | Affected versions |
|---|---|---|
| Atlassian | Questions For Confluence | 2.7.34 2.7.35 3.0.2 |
References
2 LinksRecord Details
More from Atlassian
Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability
Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability
Atlassian Jira Server and Data Center Path Traversal Vulnerability
Related Tool Categories
Tool categories that test for or protect against this vulnerability class.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.