claytonvantol.us
SESSION: secure TLS: 1.3 PID: 1337

clayton@site:~/news$ cat cve-2022-26138-atlassian-confluence.log

CVE-2022-26138 — Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability

2022-07-29 • CISA Known Exploited Vulnerability


[event] Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group.

> AFFECTED SOFTWARE

Field Value
Vendor Atlassian
Product Confluence
CWE CWE-798
CVE ID CVE-2022-26138
Date Added 2022-07-29
Due Date 2022-08-19
Ransomware Campaign Unknown

> MITIGATION

Apply updates per vendor instructions.

Due Date: 2022-08-19

> REFERENCES


← back to terminal

UPTIME: 1337d v2.0.1 privacy LAST LOGIN: 2026-05-30 20:36:11 UTC