QID 150556
Date Published: 2022-08-04
QID 150556: Atlassian Confluence Server and Data Center : Questions for Confluence App - Hardcoded Credentials (CVE-2022-26138)
Confluence is a team collaboration software. Written in Java and mainly used in corporate environments, it is developed and marketed by Atlassian.
Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password.
Affected versions:
Questions for Confluence Version 2.7.34
Questions for Confluence Version 2.7.35
Questions for Confluence Version 3.0.2
QID Detection Logic (Unauthenticated) :
This QID sends a specially-crafted HTTP POST request with hardcoded credentials to log into Confluence application and retrieve disabledsystemuser account profile page to confirm the vulnerability.
Successful exploitation of this vulnerability would allow an remote attacker with knowledge of the hardcoded credentials to log into Confluence application and access any pages the confluence-users group has access to.
- Questions For Confluence Security Advisory -
confluence.atlassian.com/doc/questions-for-confluence-security-advisory-2022-07-20-1142446709.html
CVEs related to QID 150556
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Questions For Confluence Security Advisory |
|