CVE-2022-26138
Description
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.
Summary dbcve.org
The Atlassian Questions For Confluence app (versions 2.7.34, 2.7.35, and 3.0.2) provisions a Confluence user account named 'disabledsystemuser' in the confluence-users group with a hardcoded password at install time. A remote, unauthenticated attacker who knows or obtains this hardcoded credential can authenticate to Confluence and read all content accessible to any user in the confluence-users group.
Mitigation
Upgrade the Questions For Confluence app to a fixed version, remove the 'disabledsystemuser' account from Confluence, and audit access logs for any prior authentication or activity performed by that account to determine if data was exposed.