
Atlassian Confluence Server and Data Center: CVE-2022-26138
Atlassian Confluence Server and Data Center: CVE-2022-26138
Confluence Server 또는 Data Center에 'Questions for Confluence' 앱이 설치되고 활성화되면, 사용자 이름 'disabledsystemuser'와 비밀번호 'disabled1system1user6708'을 가진 Confluence 사용자 계정이 생성됩니다. 이는 하드코딩된 비밀번호이며, 계정은 confluence-users 그룹에 추가되어 기본적으로 Confluence 애플리케이션 내 모든 비제한 페이지를 조회하고 편집할 수 있게 됩니다.
공격자는 이러한 하드코딩된 자격 증명을 사용하여 Confluence에 로그인하고 confluence-users 그룹 내의 모든 콘텐츠에 접근할 수 있습니다. 이 사용자 계정은 앱 버전 2.7.34, 2.7.35 및 3.0.2를 설치할 때 생성됩니다.
Questions for Confluence 문제를 해결하려면 Atlassian은 Questions for Confluence 앱을 보안 버전으로 업데이트하거나 disabledsystemuser 계정을 비활성화/삭제할 것을 권장합니다.
Shodan
title:Confluence
http.favicon.hash:-305179312
fofa:
icon_hash="-305179312"


Dorks:
Shodan title:Confluence http.favicon.hash:-305179312
fofa: icon_hash="-305179312"