CVE-2022-26134
Atlassian Confluence 中的一个未认证 RCE 漏洞
CVE 摘要
在受影响的 Confluence Server 和 Data Center 版本中,存在一个 OGNL 注入漏洞,该漏洞允许未认证的攻击者在 Confluence Server 或 Data Center 实例上执行任意代码。
受影响版本
- Atlassian Confluence Server
- Atlassian Confluence Data Center
- 版本 > 1.3.0 (< 7.4.17, < 7.13.7, < 7.14.3, < 7.15.2, < 7.16.4, < 7.17.4, < 7.18.1) (注意:这些都是各个单独的版本,基本上所有版本 (直到 7.4.17) 都易受攻击,但 7.13.6 不比 7.4.x 更新 -> 也易受攻击)
参考