CVE-2022-26138: Atlassian Questions For Confluence – Hardcoded Credentials

CVE-2022-26138: Atlassian Questions For Confluence - Hardcoded Credentials-渗透云记 - 专注于网络安全与技术分享
CVE-2022-26138: Atlassian Questions For Confluence – Hardcoded Credentials
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2022-26138: Atlassian Questions For Confluence – Hardcoded Credentials

漏洞描述

Atlassian Questions For Confluence contains a hardcoded credentials vulnerability. When installing versions 2.7.34, 2.7.35, and 3.0.2, a Confluence user account is created in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password can exploit this vulnerability to log into Confluence and access all content accessible to users in the confluence-users group.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享