QID 730569
Date Published: 2022-08-02
QID 730569: Atlassian Confluence Server and Confluence Data Center - Questions For Confluence App - Hardcoded Password Vulnerability (CONFSERVER-79483)
Confluence is a team collaboration software. Written in Java and mainly used in corporate environments, it is developed and marketed by Atlassian.
CVE-2022-26138: Confluence Server and Data Center unauthenticated remote code execution vulnerability.
Affected Versions:
Confluence Server and Data Center versions: 7.4.0, 7.13.0, 7.4.12, 7.16.0, 7.15.1, and 7.17.0
QID Detection Logic(Unauthenticated):
It checks for vulnerable versions of Atlassian Confluence Server.
A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access any pages the confluence-users group has access to.
Solution
Please refer to Questions For Confluence Security Advisory for further information on this vulnerability.
Vendor References
- Confluence Security Advisory -
confluence.atlassian.com/doc/questions-for-confluence-security-advisory-2022-07-20-1142446709.html
CVEs related to QID 730569
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Questions For Confluence Security Advisory |
|