Patching and checking for evidence of exploitation

Patching and checking for evidence of exploitation

2 years ago
Anonymous $Smh9ljW9Kw

https://www.bleepingcomputer.com/news/security/atlassian-confluence-hardcoded-password-was-leaked-patch-now/

Australian software firm Atlassian warned customers to immediately patch a critical vulnerability that provides remote attackers with hardcoded credentials to log into unpatched Confluence Server and Data Center servers.

As the company revealed this week, the Questions for Confluence app (installed on over 8,000 servers) creates a disabledsystemuser account with a hardcoded password to help admins migrate data from the app to the Confluence Cloud.