Latest Atlassian Confluence vulnerability raises concerns
Summary
If a malicious actor was to gain knowledge of this hardcoded password, they could exploit it remotely to log into Confluence and access any pages that the account can. The hardcoded password has since been discovered and publicly disclosed on Twitter, making CVE-2022-26138 a critical issue that will be exploited in short order. In a demonstration of how the widespread popularity of Confluence makes exploiting vulnerabilities in the service particularly attractive to bad actors, Akamai reported it saw about 100,000 exploitation attempts daily in the first days after release, falling back to 20,000 per day at the end of June, from approximately 6,000 malicious IPs – of which 50% had already been identified as such by Akamai. Akamai said it observed multiple different cyber attacks unfolding through the vulnerability, including the delivery of malicious webshells, malware and illicit cryptominers. Further to this disclosure, Rapid7’s threat intelligence team found a user on the Russian-language XSS forum selling root access to 50 enterprise networks that they had gained through CVE-2022-26134.