{"id":13972,"date":"2022-06-03T17:34:08","date_gmt":"2022-06-03T08:34:08","guid":{"rendered":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/?p=13972"},"modified":"2023-10-17T11:39:49","modified_gmt":"2023-10-17T02:39:49","slug":"confluence-server%e3%81%8a%e3%82%88%e3%81%b3data-center%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%ef%bc%88cve-2022-26134%ef%bc%89%e3%81%ab%e9%96%a2%e3%81%99%e3%82%8b%e6%b3%a8%e6%84%8f%e5%96%9a%e8%b5%b7","status":"publish","type":"post","link":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/public\/heads-up\/confluence-server%e3%81%8a%e3%82%88%e3%81%b3data-center%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%ef%bc%88cve-2022-26134%ef%bc%89%e3%81%ab%e9%96%a2%e3%81%99%e3%82%8b%e6%b3%a8%e6%84%8f%e5%96%9a%e8%b5%b7\/","title":{"rendered":"Confluence Server\u304a\u3088\u3073Data Center\u306e\u8106\u5f31\u6027\uff08CVE-2022-26134\uff09\u306b\u95a2\u3059\u308b\u6ce8\u610f\u559a\u8d77"},"content":{"rendered":"\n<p>I. \u6982\u8981<br \/>2022\u5e746\u67082\u65e5\uff08\u73fe\u5730\u6642\u9593\uff09\u3001Atlassian\u306fConfluence Server\u304a\u3088\u3073Data Center\u306e\u8106\u5f31\u6027\uff08CVE-2022-26134\uff09\u306b\u95a2\u3059\u308b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30a2\u30c9\u30d0\u30a4\u30b6\u30ea\u3092\u516c\u958b\u3057\u307e\u3057\u305f\u3002<br \/>\u672c\u8106\u5f31\u6027\u3092\u60aa\u7528\u3059\u308b\u3053\u3068\u3067\u3001\u8a8d\u8a3c\u3055\u308c\u3066\u3044\u306a\u3044\u9060\u9694\u306e\u7b2c\u4e09\u8005\u304c\u4efb\u610f\u306e\u30b3\u30fc\u30c9\u3092\u5b9f\u884c\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<br \/>\u8106\u5f31\u6027\u306e\u8a73\u7d30\u3084\u6700\u65b0\u306e\u5bfe\u7b56\u60c5\u5831\u306a\u3069\u306b\u3064\u3044\u3066\u306f\u3001Atlassian\u306e\u60c5\u5831\u3092\u78ba\u8a8d\u3057\u3066\u304f\u3060\u3055\u3044\u3002<br \/>\u53c2\u8003\uff1a<a href=\"https:\/\/www.jpcert.or.jp\/at\/2022\/at220015.html\" target=\"_blank\" rel=\"noopener\">https:\/\/www.jpcert.or.jp\/at\/2022\/at220015.html<\/a><\/p>\n<p>Atlassian<br \/>Confluence Server and Data Center &#8211; CVE-2022-26134 &#8211; Critical severity unauthenticated remote code execution vulnerability<br \/><a href=\"https:\/\/confluence.atlassian.com\/doc\/confluence-security-advisory-2022-06-02-1130377146.html\" target=\"_blank\" rel=\"noopener\">https:\/\/confluence.atlassian.com\/doc\/confluence-security-advisory-2022-06-02-1130377146.html<\/a><\/p>\n<p>Atlassian\u306f\u3001\u672c\u8106\u5f31\u6027\u3092\u60aa\u7528\u3059\u308b\u653b\u6483\u3092\u78ba\u8a8d\u3057\u3066\u3044\u307e\u3059\u3002<br \/>\u5f71\u97ff\u3092\u53d7\u3051\u308b\u88fd\u54c1\u3092\u5229\u7528\u3057\u3066\u3044\u308b\u5834\u5408\u3001Atlassian\u306a\u3069\u304b\u3089\u516c\u958b\u3055\u308c\u308b\u95a2\u9023\u60c5\u5831\u3092\u6ce8\u8996\u306e\u4e0a\u3001\u5bfe\u7b56\u3084\u56de\u907f\u7b56\u306e\u9069\u7528\u3092\u901f\u3084\u304b\u306b\u691c\u8a0e\u3044\u305f\u3060\u304f\u3053\u3068\u3092\u63a8\u5968\u3057\u307e\u3059\u3002<\/p>\n<p><br \/>II. \u5bfe\u8c61<br \/>\u5bfe\u8c61\u3068\u306a\u308b\u88fd\u54c1\u306f\u6b21\u306e\u3068\u304a\u308a\u3067\u3059\u3002<br \/>\u5f71\u97ff\u3092\u53d7\u3051\u308b\u30d0\u30fc\u30b8\u30e7\u30f3\u306a\u3069\u306e\u6700\u65b0\u306e\u60c5\u5831\u306b\u3064\u3044\u3066\u306fAtlassian\u304b\u3089\u306e\u60c5\u5831\u3092\u3054\u78ba\u8a8d\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>Confluence<br \/>&#8211; Confluence Server<br \/>&#8211; Confluence Data Center<\/p>\n<p><br \/>III. \u5bfe\u7b56<br \/>2022\u5e746\u67083\u65e5\u73fe\u5728\u3001Atlassian\u304b\u3089\u672c\u8106\u5f31\u6027\u3092\u4fee\u6b63\u3057\u305f\u30d0\u30fc\u30b8\u30e7\u30f3\u306f\u516c\u958b\u3055\u308c\u3066\u3044\u307e\u305b\u3093\u3002<br \/>Atlassian\u304b\u3089\u306e\u60c5\u5831\u3092\u6ce8\u8996\u306e\u4e0a\u3001\u5bfe\u7b56\u30d0\u30fc\u30b8\u30e7\u30f3\u304c\u516c\u958b\u3055\u308c\u6b21\u7b2c\u3001\u901f\u3084\u304b\u306b\u9069\u7528\u3092\u691c\u8a0e\u3044\u305f\u3060\u304f\u3053\u3068\u3092\u63a8\u5968\u3057\u307e\u3059\u3002<\/p>\n<p><br \/>IV. \u56de\u907f\u7b56<br \/>\u5bfe\u7b56\u30d0\u30fc\u30b8\u30e7\u30f3\u304c\u516c\u958b\u3055\u308c\u308b\u307e\u3067\u306e\u66ab\u5b9a\u7b56\u3068\u3057\u3066\u3001Atlassian\u304b\u3089\u6b21\u306e\u5bfe\u5fdc\u306e\u5b9f\u65bd\u304c\u63a8\u5968\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>&#8211; Confluence Server\u304a\u3088\u3073Confluence Data Center\u3078\u306e\u30a4\u30f3\u30bf\u30fc\u30cd\u30c3\u30c8\u304b\u3089\u306e\u63a5\u7d9a\u3092\u5236\u9650\u3059\u308b<br \/>&#8211; Confluence Server\u304a\u3088\u3073Confluence Data Center\u3092\u4e00\u6642\u7684\u306b\u7121\u52b9\u306b\u3059\u308b<\/p>\n<p><br \/>V. \u53c2\u8003\u60c5\u5831<\/p>\n<p>Volexity<br \/>Zero-Day Exploitation of Atlassian Confluence<br \/><a href=\"https:\/\/www.volexity.com\/blog\/2022\/06\/02\/zero-day-exploitation-of-atlassian-confluence\/\" target=\"_blank\" rel=\"noopener\">https:\/\/www.volexity.com\/blog\/2022\/06\/02\/zero-day-exploitation-of-atlassian-confluence\/<\/a><\/p>\n<p>Atlassian<br \/>\u30a2\u30c8\u30e9\u30b7\u30a2\u30f3 \u30b5\u30dd\u30fc\u30c8\u7d42\u4e86 (EOL) \u30dd\u30ea\u30b7\u30fc<br \/><a href=\"https:\/\/ja.confluence.atlassian.com\/support\/atlassian-support-end-of-life-policy-201851003.html\" target=\"_blank\" rel=\"noopener\">https:\/\/ja.confluence.atlassian.com\/support\/atlassian-support-end-of-life-policy-201851003.html<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I. \u6982\u89812022\u5e746\u67082\u65e5\uff08\u73fe\u5730\u6642\u9593\uff09\u3001Atlassian\u306fConfluence Server\u304a\u3088\u3073Data Center\u306e\u8106\u5f31\u6027\uff08CVE-2022-26134\uff09\u306b\u95a2\u3059\u308b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30a2\u30c9\u30d0\u30a4\u30b6\u30ea\u3092\u516c\u958b\u3057\u307e\u3057\u305f\u3002\u672c\u8106\u5f31\u6027 [&hellip;]<\/p>\n","protected":false},"author":3208,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[5],"tags":[45],"_links":{"self":[{"href":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/wp-json\/wp\/v2\/posts\/13972"}],"collection":[{"href":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/wp-json\/wp\/v2\/users\/3208"}],"replies":[{"embeddable":true,"href":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/wp-json\/wp\/v2\/comments?post=13972"}],"version-history":[{"count":1,"href":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/wp-json\/wp\/v2\/posts\/13972\/revisions"}],"predecessor-version":[{"id":13973,"href":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/wp-json\/wp\/v2\/posts\/13972\/revisions\/13973"}],"wp:attachment":[{"href":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/wp-json\/wp\/v2\/media?parent=13972"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/wp-json\/wp\/v2\/categories?post=13972"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/wp-json\/wp\/v2\/tags?post=13972"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}