{"id":25838,"date":"2022-07-21T22:16:32","date_gmt":"2022-07-21T20:16:32","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=25838"},"modified":"2022-07-21T22:19:24","modified_gmt":"2022-07-21T20:19:24","slug":"confluence-security-advisory-2022-07-20","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2022\/07\/21\/confluence-security-advisory-2022-07-20\/","title":{"rendered":"Confluence Security Advisory 2022-07-20"},"content":{"rendered":"<p><img decoding=\"async\" title=\"Sicherheit (Pexels, allgemeine Nutzung)\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" alt=\"Sicherheit (Pexels, allgemeine Nutzung)\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Sicherheit_klein.jpg\" width=\"200\" align=\"left\">[<a href=\"https:\/\/www.borncity.com\/blog\/2022\/07\/21\/confluence-security-advisory-2022-07-20\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]Confluence released Security Advisory <a href=\"https:\/\/confluence.atlassian.com\/doc\/questions-for-confluence-security-advisory-2022-07-20-1142446709.html\" target=\"_blank\" rel=\"noopener\">2022-07-20<\/a> on July 20, and updated it today. The security advisory addresses Confluence accounts with hardcoded credentials created by Questions for Confluence. This affects the Confluence app for Confluence Server and Confluence Data Center. <\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/vg04.met.vgwort.de\/na\/f83dbc68d02f48dc9f267ea8bbdf3e29\" width=\"1\" height=\"1\">When the Questions for Confluence app is enabled on Confluence Server or Data Center, the app creates a Confluence user account with the username <em>disabledsystemuser<\/em>. This account is intended for administrators migrating data from the app to Confluence Cloud. <\/p>\n<p>The <em>disabledsystemuser<\/em> account is created with a hard-coded password and added to the <em>confluence-users<\/em> group. By default, the group allows viewing and editing of all unrestricted pages in Confluence. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all pages to which the <em>confluence-users<\/em> group has access.<\/p>\n<p>This hardcoded password vulnerability was <a href=\"https:\/\/twitter.com\/fluepke\/status\/1549892089181257729\" target=\"_blank\" rel=\"noopener\">discovered<\/a> by an external security researcher and disclosed on Twitter. Confluence classifies the vulnerability as critical. Since the hardcoded password is now publicly known, it is likely that this issue will be exploited in the wild. This vulnerability should be fixed immediately on affected systems. Confluence Server or Data Center instances are affected if this has an active user account with the following information:<\/p>\n<ul>\n<p>User: disabledsystemuser <br \/>Username: disabledsystemuser <br \/>Email: dontdeletethisuser@email.com<\/p>\n<\/ul>\n<p>It is possible for this account to exist if the Questions for Confluence app was previously installed and uninstalled. The following app versions are affected:<\/p>\n<ul>\n<li>Questions for Confluence 2.7.34 und 2.7.35 und 3.0.2<\/li>\n<\/ul>\n<p>Questions for Confluence 2.7.34 and 2.7.35 and 3.0.2.<br \/>Confluence has provided updated versions of the app. In addition, user accounts can be disabled and deleted. For details on how to fix this vulnerability, see Security Advisory <a href=\"https:\/\/confluence.atlassian.com\/doc\/questions-for-confluence-security-advisory-2022-07-20-1142446709.html\" target=\"_blank\" rel=\"noopener\">2022-07-20<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Confluence released Security Advisory 2022-07-20 on July 20, and updated it today. The security advisory addresses Confluence accounts with hardcoded credentials created by Questions for Confluence. This affects the Confluence app for Confluence Server and Confluence Data Center.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,1547],"tags":[69,1544],"class_list":["post-25838","post","type-post","status-publish","format-standard","hentry","category-security","category-software","tag-security","tag-software"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/25838","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=25838"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/25838\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=25838"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=25838"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=25838"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}