Atlassian Rolls Out Security Patch for Critical Confluence Vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-26136 +1 in the same advisory: …26137 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4. NVD description · AI analysis pending | 9.8 group max | 5% |
| — | ||
| CVE-2022-26138 | Hard-coded Credentials in Atlassian Questions for Confluence App The Questions for Confluence app for Confluence Server and Data Center, when versions 2.7.34, 2.7.35, or 3.0.2 are installed, creates a user account named disabledsystemuser in the confluence-users group protected by a hard-coded password (CWE-798). Because the credential is embedded in the app, any remote, unauthenticated attacker who knows the password can log in to Confluence without a valid account. Successful exploitation grants access to all content that is accessible to the confluence-users group, which typically spans most of the instance's spaces and pages. Only Confluence Server and Data Center deployments that installed one of those app versions are affected, and the created account persists after installation. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-07-29 and carries a 98.2% EPSS score (100th percentile). Do: Upgrade the Questions for Confluence app to a fixed release per Atlassian's instructions, as required by the CISA KEV catalog. Check whether an account named disabledsystemuser exists in the confluence-users group; if present, delete it or change its hard-coded password, and review authentication logs for logins using that account. Prioritize internet-exposed Confluence Server and Data Center instances. | 9.8 | 98% | KEV |
| moderatelikely thousands of Confluence Server/Data Center instances (only those that installed the three named app versions) |
Full article517 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJul 21, 2022
Atlassian has rolled out fixes to remediate a critical security vulnerability pertaining to the use of hard-coded credentials affecting the Questions For Confluence app for Confluence Server and Confluence Data Center.
The flaw, tracked as CVE-2022-26138, arises when the app in question is enabled on either of two services, causing it to create a Confluence user account with the username "disabledsystemuser."
While this account, Atlassian says, is to help administrators migrate data from the app to Confluence Cloud, it's also created with a hard-coded password, effectively allowing viewing and editing all non-restricted pages within Confluence by default.
"A remote, unauthenticated attacker with knowledge of the hard-coded password could exploit this to log into Confluence and access any pages the confluence-users group has access to," the company said in an advisory, adding that "the hard-coded password is trivial to obtain after downloading and reviewing affected versions of the app."
Questions for Confluence versions 2.7.34, 2.7.35, and 3.0.2 are impacted by the flaw, with fixes available in versions 2.7.38 and 3.0.5. Alternatively, users can disable or delete the disabledsystemuser account.
While Atlassian has pointed out that there's no evidence of active exploitation of the flaw, users can look for indicators of compromise by checking the last authentication time for the account. "If the last authentication time for disabledsystemuser is null, that means the account exists but no one has ever logged into it," it said.
Separately, the Australian software company also moved to patch a pair of critical flaws, which it calls servlet filter dispatcher vulnerabilities, impacting multiple products -
- Bamboo Server and Data Center
- Bitbucket Server and Data Center
- Confluence Server and Data Center
- Crowd Server and Data Center
- Fisheye and Crucible
- Jira Server and Data Center, and
- Jira Service Management Server and Data Center
Successful exploitation of the bugs, tracked as CVE-2022-26136 and CVE-2022-26137, could enable an unauthenticated, remote attacker to bypass authentication used by third-party apps, execute arbitrary JavaScript code, and circumvent the cross-origin resource sharing (CORS) browser mechanism by sending a specially crafted HTTP request.
"Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability," the company cautioned in its advisory regarding CVE-2022-26137.
Update: Atlassian on Thursday warned that the critical Questions For Confluence app vulnerability is likely to be exploited in the wild after the hard-coded password became publicly known, urging its customers to remediate the issue as soon as possible.
"An external party has discovered and publicly disclosed the hardcoded password on Twitter," the company said. "It is important to remediate this vulnerability on affected systems immediately."
The software firm also emphasized that uninstalling the Questions for Confluence app does not address the vulnerability, as the created account does not get automatically removed after the app has been uninstalled. It's instead recommending that users either update to the latest version of the app or manually disable or delete the account.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/07/atlassian-releases-patch-for-critical.html