> A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group
A hardcoded password... are these guys for real?
A hardcoded password... are these guys for real?
[0] https://www.theguardian.com/australia-news/2020/jul/09/austr...
Gitlab had the same issue just a few months ago.
in comparison to that, disabled1system1user6708 seems pretty weak
Using this method we can see that this password (disabled1system1user6708) would take over 10,000 centuries to brute force
That seems relatively secure to me