Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-26138
HistoryJul 20, 2022 - 6:15 p.m.

Hardcoded credentials

2022-07-2018:15:00
PRIOn knowledge base
www.prio-n.com
10

9.5 High

AI Score

Confidence

High

0.972 High

EPSS

Percentile

99.8%

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.