QID 376657
Date Published: 2022-06-07
QID 376657: Atlassian Confluence Server and Confluence Data Center Remote Code Execution (RCE) Vulnerability (CONFSERVER-79016)
Confluence is a team collaboration software. Written in Java and mainly used in corporate environments, it is developed and marketed by Atlassian.
CVE-2022-26134: Confluence Server and Data Center unauthenticated remote code execution vulnerability.
Affected Versions:
Confluence Server and Data Center versions after 1.3.0 and prior to 7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, and 7.18.1 are affected
QID Detection Logic(authenticated):
Operating System: (Windows)
The QID checks for vulnerable versions of Confluence Server.
Note: The QID will only detect MSI installation on Windows.
Note: Currently, the QID is a potential detection because it does not check if mitigations are applied instead of the patch. The QID will be updated soon to be a confirmed detection.
Operating System: (Unix)
The QID checks for vulnerable versions of Confluence Server and checks for mitigation advised by the vendor.
Successful Exploitation of this vulnerability may allow an unauthenticated attacker to execute arbitrary code on the target system.
- Confluence Security Advisory -
confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html
CVEs related to QID 376657
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Confluence Security Advisory |
|