Close Menu
Aviation Analysis – Industry Travel NewsAviation Analysis – Industry Travel News
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Aviation Analysis – Industry Travel NewsAviation Analysis – Industry Travel News
    Subscribe
    • Home
    • Top News
    • World
    • Economy
    • Science
    • Tech
    • Sport
    • Entertainment
    • Contact Form
    Aviation Analysis – Industry Travel NewsAviation Analysis – Industry Travel News
    Home»Tech»User account with default password puts Atlassian Confluence at risk
    Tech

    User account with default password puts Atlassian Confluence at risk

    Theodore MeeksBy Theodore MeeksJuly 21, 2022No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email
    User account with default password puts Atlassian Confluence at risk
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    Atlassian’s Convergence server wiki software and Data Center wiki software are weak. The developers assure that Confluence Cloud is not affected by the vulnerability.

    However, systems are only vulnerable if the Confluence App Q&A app is installed. If this is the case, the app for Confluence Server and Data Center automatically creates an account with the username ‘System Canceled’. A default password is set when it is generated, which attackers can obtain with relatively little effort.

    Systems affected?

    Equipped with this, they can access all unrestricted wiki pages by default. In a warning, the developers classify the vulnerability (CVE-2022-26138) as “criticalA. Atlassian confirmed that they have not detected any attacks yet.

    Administrators should check their Confluence installations to see if there is an account with the following data:

    • User: disable the system
    • Username: disable the system
    • Email: [email protected]

    If so, they should act. Confluence Question versions 2.7.34, 2.7.35 and 3.0.2 are particularly affected.

    Act now!

    Uninstalling the app does not solve the security issue because the account remains. To secure systems, administrators need to fix Issue 7/2/38 or 3.0.5 to install. Alternatively, you can deactivate or remove the account.

    By looking at the list of registered users, one can check if the attackers have already exploited the vulnerability. The developers describe how this works in an article.


    (From)

    to the home page

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Theodore Meeks

    Lifelong foodaholic. Professional twitter expert. Organizer. Award-winning internet geek. Coffee advocate.

    Related Posts

    Neodymium Magnet Uses and Safety Tips for 2025

    October 4, 2025

    Halifax Stanfield Airport Pilots Passenger Service Robots in Bid to Boost Traveler Experience

    August 25, 2025

    Battery miracle in test – HP Omnibook X AI: If it takes longer again

    August 29, 2024
    Navigate
    • Home
    • Top News
    • World
    • Economy
    • Science
    • Tech
    • Sport
    • Entertainment
    • Contact Form
    Pages
    • About Us
    • DMCA
    • Contact Form
    • Privacy Policy
    • Editorial Policy
    STAY UPTODATE

    Get the Latest News With Aviationanalysis.net

    OFFICE

    X. Herald Inc.
    114 5th Ave New York,
    NY 10011, United States

    QUERIES?

    Do you have any queries? Feel free to contact us via our Contact Form

    Visit Our Office

    X. Herald Inc.
    114 5th Ave New York,
    NY 10011, United States

    • About Us
    • DMCA
    • Contact Form
    • Privacy Policy
    • Editorial Policy
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.