Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability
Confluence Server 및 Data Center용 Atlassian Questions For Confluence 앱은 사용자 이름이 disabledsystemuser이고 하드코딩된 비밀번호를 사용하는 Confluence 사용자 계정을 confluence-users 그룹에 생성합니다. 하드코딩된 비밀번호를 아는 인증되지 않은 원격 공격자는 이를 악용해 Confluence에 로그인하고 confluence-users 그룹의 사용자가 접근할 수 있는 모든 콘텐츠에 접근할 수 있습니다. 이 사용자 계정은 앱의 2.7.34, 2.7.35 및 3.0.2 버전을 설치할 때 생성됩니다.
Confluence Server 및 Data Center용 Atlassian Questions For Confluence 앱은 사용자 이름이 disabledsystemuser이고 하드코딩된 비밀번호를 사용하는 Confluence 사용자 계정을 confluence-users 그룹에 생성합니다. 하드코딩된 비밀번호를 아는 인증되지 않은 원격 공격자는 이를 악용해 Confluence에 로그인하고 confluence-users 그룹의 사용자가 접근할 수 있는 모든 콘텐츠에 접근할 수 있습니다. 이 사용자 계정은 앱의 2.7.34, 2.7.35 및 3.0.2 버전을 설치할 때 생성됩니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.