CVE-2022-26134

Description

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
94.408

Associated Vulnerability

VulnerabilityOS Platform
Remote code execution in Atlassian Confluence Server (CVE-2022-26134)Windows
Remote code execution in Atlassian Jira (CVE-2022-26134)Windows
Vulnerabilities CVE-2022-26134 are affected in Atlassian Confluence 7.13.6Windows
Vulnerabilities CVE-2022-26134,CVE-2022-26136,CVE-2022-26137 are affected in Atlassian Confluence 7.14.2Windows
Vulnerabilities CVE-2022-26134,CVE-2022-26136,CVE-2022-26137 are affected in Atlassian Confluence 7.15.1Windows
Vulnerabilities CVE-2022-26134,CVE-2022-26136,CVE-2022-26137 are affected in Atlassian Confluence 7.16.3Windows
Vulnerabilities CVE-2022-26134,CVE-2022-26136,CVE-2022-26137 are affected in Atlassian Confluence 7.17.3Windows
Vulnerabilities CVE-2022-26134,CVE-2022-26136,CVE-2022-26137 are affected in Atlassian Confluence 7.18.0Windows
Vulnerabilities CVE-2022-26134,CVE-2022-26136,CVE-2022-26137 are affected in Atlassian Confluence 7.4.16Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234