Code Injection in Confluence Server and Jira Software Data Center - CVE-2022-26134

 

Code Injection in Confluence Server and Jira Software Data Center - CVE-2022-26134

Published: June 3, 2022 / Updated: June 21, 2024


Vulnerability identifier: #VU63958
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-26134
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper input validation when processing OGNL expressions. A remote non-authenticated attacker can send a specially crafted request to the Confluence Server and execute arbitrary code on the system.

Note, the vulnerability is being actively exploited in the wild.

Affected software

Confluence Server
Jira Software Data Center

How to mitigate CVE-2022-26134

Install update from vendor's website.

Confluence Server - addressed in versions 7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, 7.18.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins