Skip to content

  • Home
  • Top News
  • World
  • Economy
  • Science
  • Tech
  • Sport
  • Entertainment
  • Contact Form

User account with default password puts Atlassian Confluence at risk

User account with default password puts Atlassian Confluence at risk

Theodore Meeks, July 21, 2022

Atlassian’s Convergence server wiki software and Data Center wiki software are weak. The developers assure that Confluence Cloud is not affected by the vulnerability.

However, systems are only vulnerable if the Confluence App Q&A app is installed. If this is the case, the app for Confluence Server and Data Center automatically creates an account with the username ‘System Canceled’. A default password is set when it is generated, which attackers can obtain with relatively little effort.

Systems affected?

Equipped with this, they can access all unrestricted wiki pages by default. In a warning, the developers classify the vulnerability (CVE-2022-26138) as “criticalA. Atlassian confirmed that they have not detected any attacks yet.

Administrators should check their Confluence installations to see if there is an account with the following data:

  • User: disable the system
  • Username: disable the system
  • Email: dontdeletethisuser@email.com

If so, they should act. Confluence Question versions 2.7.34, 2.7.35 and 3.0.2 are particularly affected.

Act now!

Uninstalling the app does not solve the security issue because the account remains. To secure systems, administrators need to fix Issue 7/2/38 or 3.0.5 to install. Alternatively, you can deactivate or remove the account.

By looking at the list of registered users, one can check if the attackers have already exploited the vulnerability. The developers describe how this works in an article.


(From)

to the home page

Theodore Meeks

Lifelong foodaholic. Professional twitter expert. Organizer. Award-winning internet geek. Coffee advocate.

Tech

Post navigation

Previous post
Next post

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Navigate

  • Home
  • Top News
  • World
  • Economy
  • Science
  • Tech
  • Sport
  • Entertainment
  • Contact Form

Pages

  • About Us
  • DMCA
  • Contact Form
  • Privacy Policy
  • Editorial Policy

Pages

  • About Us
  • Contact Form
  • DMCA
  • Editorial Policy
  • Privacy Policy

STAY UPTODATE

Get the Latest News With Aviationanalysis.net

OFFICE

X. Herald Inc.
114 5th Ave New York,
NY 10011, United States

QUERIES?

Do you have any queries? Feel free to contact us via our Contact Form

Visit Our Office

X. Herald Inc.
114 5th Ave New York,
NY 10011, United States

©2025 | WordPress Theme by SuperbThemes
  • Home
  • Top News
  • World
  • Economy
  • Science
  • Tech
  • Sport
  • Entertainment
  • Contact Form