Atlassian Questions for Confluence 2.7.34

CPE Details

Atlassian Questions for Confluence 2.7.34
2.7.34
2022-08-04
12h13 +00:00
2022-08-11
14h54 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:atlassian:questions_for_confluence:2.7.34:*:*:*:*:*:*:*

Informations

Vendor

atlassian

Product

questions_for_confluence

Version

2.7.34

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-26138 2022-07-20 17h25 +00:00 The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.
9.8
Critical