SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2022-26134

Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability

KEVCRITICAL 9.8EPSS 100.0%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 6 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
100.00% probability · 100th percentile
CISA KEV
Listed 2 June 2022 · due 6 June 2022 · used in ransomware campaigns
Weakness
CWE-917
Affected
atlassian/confluence data center · atlassian/confluence server
Source
security@atlassian.com

CISA notes

Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules. https://nvd.nist.gov/vuln/detail/CVE-2022-26134

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.