CVE-2022-26134
Description
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.
Summary dbcve.org
An OGNL (Object-Graph Navigation Language) injection vulnerability in affected versions of Confluence Server and Data Center allows an unauthenticated remote attacker to execute arbitrary code on the underlying server. Exploitation requires no credentials and is reachable over the network, making it critical for any internet-exposed or untrusted-network Confluence instance.
Mitigation
Upgrade Confluence Server and Data Center to a fixed version per Atlassian's advisory: 7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, or 7.18.1 (or later), and verify no indicators of prior compromise are present.