← All CVEs

CVE-2022-26134

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules.

Added 2022-06-02Remediation due 2022-06-06

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

9.8
CVSS
100.0%
EPSS (exploit prob.)
100th
EPSS percentile
2022-06-03
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-917

Affected products

VendorProductAffected versions
atlassianconfluence_data_center>= 1.3, < 7.4.17
atlassianconfluence_data_center>= 7.13.0, < 7.13.7
atlassianconfluence_data_center>= 7.14.0, < 7.14.3
atlassianconfluence_data_center>= 7.15.0, < 7.15.2
atlassianconfluence_data_center>= 7.16.0, < 7.16.4
atlassianconfluence_data_center>= 7.17.0, < 7.17.4
atlassianconfluence_data_center7.18.0
atlassianconfluence_server>= 1.3, < 7.4.17
atlassianconfluence_server>= 7.13.0, < 7.13.7
atlassianconfluence_server>= 7.14.0, < 7.14.3
atlassianconfluence_server>= 7.15.0, < 7.15.2
atlassianconfluence_server>= 7.16.0, < 7.16.4
atlassianconfluence_server>= 7.17.0, < 7.17.4
atlassianconfluence_server7.18.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-26134