Atlassian Questions For Confluence 2.7.34 / 2.7.35 / 3.0.2 Hardcoded Credentials

critical Web App Scanning Plugin ID 113328

Synopsis

Atlassian Questions For Confluence 2.7.34 / 2.7.35 / 3.0.2 Hardcoded Credentials

Description

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group.

Uninstalling the Questions for Confluence app does not remediate this vulnerability. The account does not automatically get removed after the app has been uninstalled.

Solution

Update your Questions for Confluence plugin to 2.7.38 or 3.0.5 or later or search for the disabledsystemuser account and either disable it or delete it.

See Also

https://confluence.atlassian.com/doc/confluence-security-advisory-2022-07-20-1142446709.html

https://jira.atlassian.com/browse/CONFSERVER-79483

Plugin Details

Severity: Critical

ID: 113328

Type: remote

Published: 8/8/2022

Updated: 12/19/2022

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2022-26138

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS Score Source: CVE-2022-26138

Vulnerability Information

CPE: cpe:2.3:a:atlassian:confluence:*:*:*:*:*:*:*:*

Exploit Available: true

Exploit Ease: Exploits are available

CISA Known Exploited Vulnerability Due Dates: 8/19/2022

Reference Information

CVE: CVE-2022-26138