Atlassian Questions for Confluence 3.0.2

CPE Details

Atlassian Questions for Confluence 3.0.2
3.0.2
2022-08-04
12h13 +00:00
2022-08-11
14h53 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:atlassian:questions_for_confluence:3.0.2:*:*:*:*:*:*:*

Informations

Vendor

atlassian

Product

questions_for_confluence

Version

3.0.2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-26138 2022-07-20 17h25 +00:00 The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.
9.8
Critical