What's Hot

    Ashok Sharma was awarded by Noon as Iconic Enterprise Entrepreneur in Dubai which was marked by the presence of many Bollywood celebrities, Enterprise man and well-known personalities

    November 27, 2022

    Suresh Kumar Kosagi was awarded as Noon greatest capital administration advisor by Esha Khoplekar in Dubai which was marked by the presence of many Bollywood celebrities, businessmen, and well-known personalities.

    November 26, 2022

    Atlassian Confluence Bug Beneath Lively Exploit

    July 28, 2022
    Facebook Twitter Instagram
    • About Us
    • Contact Us
    • Disclaimer
    • Terms and Conditions
    • Privacy Policy
    Facebook Twitter Instagram
    Bluebear-CyberBluebear-Cyber
    • Home
    • News
    • Top
      • Top 10 Brands
      • Top 20 Brands
    • Brand
      • Brand Listing
      • Brand Information
    • Press Release
    • Promotion And Offer
    • More
      • Best Products
      • Product Rating
      • Reviews
    Bluebear-CyberBluebear-Cyber
    Home»Uncategorized»Atlassian Confluence Bug Beneath Lively Exploit
    Uncategorized

    Atlassian Confluence Bug Beneath Lively Exploit

    EditorBy EditorJuly 28, 2022No Comments2 Mins Read

    A crucial Atlassian Confluence vulnerability that was disclosed final week is now being actively exploited within the wild, researchers are warning.

    Based on researchers at Rapid7, the bug in query (CVE-2022-26138, one of three patched last week) is because of a hardcoded password within the Questions for Confluence app, which might enable cyberattackers to realize full entry to knowledge inside the on-premises Confluence Server and Confluence Information Heart platforms.

    Extra particularly, as soon as put in, the Questions for Confluence app will “create a person account with a hard-coded password and add the account to a person group, which permits entry to all nonrestricted pages in Confluence,” in response to Rapid7’s posting. “This simply permits a distant, unauthenticated attacker to browse a company’s Confluence occasion.”

    The stakes are excessive. Many organizations use Confluence for mission administration and collaboration amongst groups scattered throughout on-premises and distant places. Usually Confluence environments can home delicate knowledge on initiatives that a company is likely to be engaged on, or home it on its prospects and companions.

    Organizations are urged to patch rapidly as a result of the password was made public final week, prompting emergency motion by Atlassian. Confluence is sadly a well-liked goal for attackers, as evidenced by the active exploitation of the bug tracked as CVE-2022-26134 in June, used to unfold ransomware.

    Admins ought to word: The bug solely exists when the Questions for Confluence app is enabled, and it doesn’t affect the Confluence Cloud occasion. Nonetheless, crucially, “uninstalling the Questions for Confluence app doesn’t remediate this vulnerability,” in response to Atlassian’s advisory final week.

    “Confluence has had no scarcity of headlines,” Rick Holland, CISO at Digital Shadows, stated by way of electronic mail. “Hardcoded passwords considerably enhance the probability of exploitation, particularly when the passwords develop into broadly shared. In case you play soccer, hardcoded passwords are ‘personal targets.’ Adversaries rating sufficient targets alone; we need not put the ball in our personal web. By no means use hardcoded passwords; take the time to arrange correct authentication and decrease future dangers.”

    Share. Facebook Twitter LinkedIn

    Related Posts

    Ashok Sharma was awarded by Noon as Iconic Enterprise Entrepreneur in Dubai which was marked by the presence of many Bollywood celebrities, Enterprise man and well-known personalities

    November 27, 2022

    Suresh Kumar Kosagi was awarded as Noon greatest capital administration advisor by Esha Khoplekar in Dubai which was marked by the presence of many Bollywood celebrities, businessmen, and well-known personalities.

    November 26, 2022

    Commit Digital 2021: The Way forward for Cloud-Native Safety

    July 28, 2022

    Auto-launching HiddAd on Google Play Retailer discovered in additional than 6 million downloads

    July 28, 2022
    Add A Comment

    Leave A Reply Cancel Reply

    five × five =

    This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

    Editors Picks

    Safety Dashboard Demo

    May 30, 2022

    Day 4: Safety Stopped Us At A Nationwide Park… (Baja Mexico Journey)

    May 30, 2022

    34C3 – Safety Nightmares 0x12

    May 30, 2022

    kleiner & großer Safety Schein / §34a Schein / Was gibt es wirklich, und wie bekomme ich die?

    May 30, 2022
    Latest Posts

    Mag Expo Attracts Leading Brands to Showcase Latest Mobile Accessories Tech

    February 23, 2023

    36C3 – Safety Nightmares 0x14

    May 30, 2022

    India raises windfall tax on crude, diesel, aviation gas

    January 3, 2023
    Advertisement

    Bluebear-Cyber is a place covering all the field which includes Phone Security,Web Securit,Pc Security,Antivirus protection and many more. it is covering every sector from top to bottom.
    We're social. Connect with us:

    Trending News

    Foxconn’s Covid-hit China plant near resuming full manufacturing: Report

    January 3, 2023

    IIT Bombay’s Entrepreneurship Cell launches twenty fifth version of Eureka!

    October 19, 2022

    States demand extra funds in pre-budget assembly with Nirmala Sitharaman

    November 25, 2022
    © Copyright 2023 Blue Bear Cyber.
    • About Us
    • Contact Us
    • Terms and Conditions
    • Privacy Policy
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.