QID 730514
Date Published: 2022-06-03
QID 730514: Atlassian Confluence Server and Confluence Data Center Remote Code Execution (RCE) Vulnerability (CONFSERVER-79016) (Unauthenticated Check)
Confluence is a team collaboration software. Written in Java and mainly used in corporate environments, it is developed and marketed by Atlassian.
CVE-2022-26134: Confluence Server and Data Center unauthenticated remote code execution vulnerability.
Affected Versions:
Confluence Server and Data Center versions after 1.3.0 and prior to 7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, and 7.18.1 are affected
QID Detection Logic(Unauthenticated):
The QID sends a specially crafted payload using HTTP GET requests to find vulnerable instances.
Successful Exploitation of this vulnerability may allow an unauthenticated attacker to execute arbitrary code on the target system.
Solution
Please refer to Confluence Security Advisory for further information on this vulnerability.
Vendor References
- Confluence Security Advisory -
confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html
CVEs related to QID 730514
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Confluence Security Advisory - 2019-12-18 |
|