CVE-2022-26134
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules.
תיאור (מקור, אנגלית)
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-917
מוצרים מושפעים
atlassian: confluence data center; atlassian: confluence server
קישורים
- https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1… Vendor Advisory
- https://jira.atlassian.com/browse/CONFSERVER-79016 Issue TrackingPatchVendor Advisory
- https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1… Vendor Advisory
- https://jira.atlassian.com/browse/CONFSERVER-79016 Issue TrackingPatchVendor Advisory
- http://packetstormsecurity.com/files/167430/Confluence-OGNL-Injection-Remote-C… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/167449/Atlassian-Confluence-Namespace-OGN… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/167430/Confluence-OGNL-Injection-Remote-C… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/167449/Atlassian-Confluence-Namespace-OGN… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/167431/Through-The-Wire-CVE-2022-26134-Co… Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/167432/Confluence-OGNL-Injection-Proof-Of… Third Party AdvisoryVDB Entry