Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Fix for CVE-2022-26134 may be ineffective

Steven Mezzadri June 13, 2022

When the vulnerability was announced last week, we powered off our server until the patch was made available, and then applied it.  We are running Confluence Server 7.13.7 LTS.

Earlier today, Sophos Antivirus for Linux (running on our Confluence Server) detected a virus:

Path: /var/atlassian/application-data/confluence/temp/upload_fd4c861b_e75a_4310_ae4e_5b10c650bebc_00000009.tmp

What was detected: Troj/WebShel-CS

We require 2FA authentication to login to Confluence, so I'm not sure how this was uploaded, unless some vulnerability still exists?

2 answers

1 accepted

1 vote
Answer accepted
Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
June 14, 2022

Hi Steven,

I created this support case on your behalf over in https://getsupport.atlassian.com/servicedesk/customer/portal/14/CSP-307744

I expect that our Confluence support team will want to gather logs from your environment in order to make sure that your system has been upgraded to a fixed version for this CVE.

Steven Mezzadri June 16, 2022

Thanks, Confluence support determined that the system was already compromised before the patch was applied, so we rolled back several more days.

0 votes
Ed Letifov _TechTime - New Zealand_
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
June 13, 2022

Hello, @Steven Mezzadri 

Based on file name and location this could be a regular file upload via Confluence (unrelated to CVE-2022-26134). 

I suggest you actually raise it with Atlassian support and conduct some form of forensic analysis to understand how this file got there.

Atlassian support might be able to assist, that is assuming they are actually interested to confirm that it's NOT due to ineffective fix.

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
VERSION
7.13.7
TAGS
AUG Leaders

Atlassian Community Events