Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

6.x LTS version .

feng hong September 1, 2021

cause CVE-2021-26084 .. we want to upgrade the server version from 6.9.1 to a LTS version like  6.13.23 (LTS ?)

 

but i can't find any 6.13.23version in docker hub?

 

 

1 answer

0 votes
Daniel Eads
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
September 2, 2021

Hi @feng hong ,

We're checking in on the build for 6.13.23 as we do expect that to be visible for you on Docker Hub. I'll update you as soon as it's available.

In the meantime, I would suggest not waiting for that version to mitigate CVE-2021-26084. My suggestion to you would be:

  1. Update now to 6.13.21 using one of the available images on docker hub (note: this particular version is still vulnerable)
  2. Mitigate the issue using the mitigation script and instructions in the security advisory

And then once 6.13.23 is available on docker hub, upgrade to that version.

Cheers,
Daniel | Atlassian Support

Daniel Eads
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
September 2, 2021
Oriol Albareda September 3, 2021

Hello @Daniel Eads ,

I'm waiting for 6.13.23 because of the CVE-2021-26084, but currently I'm using the 6.13.21-adoptopenjdk8 image, so I want to update it to the 6.13.23-adoptopenjdk8. I guess that this version is being built or something similar... I'm correct?

Thank you

Daniel Eads
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
September 7, 2021

Hey @Oriol Albareda ! Sorry about the confusion here - starting in Confluence 6.13, AdoptOpenJDK is the default JRE. While the image noted doesn't specifically have the -adoptopenjdk8 tag, that is the JRE being used for that image.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events