CISA Warns of Atlassian Confluence Hard-Coded Credential Bug Exploited in Attacks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-26138 | Hard-coded Credentials in Atlassian Questions for Confluence App The Questions for Confluence app for Confluence Server and Data Center, when versions 2.7.34, 2.7.35, or 3.0.2 are installed, creates a user account named disabledsystemuser in the confluence-users group protected by a hard-coded password (CWE-798). Because the credential is embedded in the app, any remote, unauthenticated attacker who knows the password can log in to Confluence without a valid account. Successful exploitation grants access to all content that is accessible to the confluence-users group, which typically spans most of the instance's spaces and pages. Only Confluence Server and Data Center deployments that installed one of those app versions are affected, and the created account persists after installation. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-07-29 and carries a 98.2% EPSS score (100th percentile). Do: Upgrade the Questions for Confluence app to a fixed release per Atlassian's instructions, as required by the CISA KEV catalog. Check whether an account named disabledsystemuser exists in the confluence-users group; if present, delete it or change its hard-coded password, and review authentication logs for logins using that account. Prioritize internet-exposed Confluence Server and Data Center instances. | 9.8 | 98% | KEV |
| moderatelikely thousands of Confluence Server/Data Center instances (only those that installed the three named app versions) |
Full article289 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJul 30, 2022
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added the recently disclosed Atlassian security flaw to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
The vulnerability, tracked as CVE-2022-26138, concerns the use of hard-coded credentials when the Questions For Confluence app is enabled in Confluence Server and Data Center instances.
"A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group," CISA notes in its advisory.
Depending on the page restrictions and the information a company has in Confluence, successful exploitation of the shortcoming could lead to the disclosure of sensitive information.
Although the bug was addressed by the Australian software company last week in versions 2.7.38 and 3.0.5, it has since come under active exploitation, cybersecurity firm Rapid7 disclosed this week.
"Exploitation efforts at this point do not seem to be very widespread, though we expect that to change," Erick Galinkin, principal AI researcher at Rapid7, told The Hacker News.
"The good news is that the vulnerability is in the Questions for Confluence app and not in Confluence itself, which reduces the attack surface significantly."
With the flaw now added to the catalog, Federal Civilian Executive Branch (FCEB) in the U.S. are mandated to apply patches by August 19, 2022, to reduce their exposure to cyberattacks.
"At this point, the vulnerability has been public for a relatively short amount of time," Galinkin noted. "Coupled with the absence of meaningful post-exploitation activity, we don't yet have any threat actors attributed to the attacks."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/07/cisa-warns-of-atlassian-confluence-hard.html