Executive brief
The Atlassian Questions For Confluence app creates a local user account with the username 'disabledsystemuser' and a hardcoded password. A remote, unauthenticated attacker with knowledge of these credentials can log into Confluence and access all content available to the confluence-users group.
Affected products
- Atlassian Questions For Confluence 2.7.34, 2.7.35, 3.0.2
- Atlassian Confluence Server
- Atlassian Confluence Data Center
Timeline
- 2022-07-20: disclosed: Initial disclosure by Atlassian and NVD publication.
- 2022-07-29: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.