Exploited Vulnerabilities Daily
🌐 日本語

ホーム › Atlassian

CVE-2022-26138: Atlassian Confluence

EPSS98.2%KEV 1739件中262位
CVEの年2022同じ年に追加
同じベンダーの登録13
同じ製品の登録1
項目内容
ベンダーAtlassian
製品Confluence
脆弱性の名前Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability
KEVへの追加日2022年7月29日
米政府機関の対応期限2022年8月19日
ランサムウェアでの悪用不明
CWECWE-798

CISAの説明(英語)

Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group.

NVD — CVE-2022-26138

CISAの既知の悪用された脆弱性カタログ(KEV)のデータです。EPSSはFIRSTが公表する「今後30日以内に悪用が観測される確率」の推定値で、週1回更新しています。対応は必ず各ベンダーの公式情報に従ってください。
このページについて

2022年7月29日にCISAの既知の悪用された脆弱性カタログ(KEV)に追加された、AtlassianのConfluenceの脆弱性です。