Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

CVE-2021-26085

gan gan
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
October 25, 2021

受影响版本的Atlassian Confluence Server允许远程攻击者通过/s/端点的“预授权任意文件读取”漏洞查看受限资源。受影响的版本为7.4.10之前和7.5.0之前的版本。
可以查看我们服务器端任意文件

此漏洞的严重性以及官方是否有补漏方法

2 answers

1 vote
Ollie Guan
Community Champion
October 25, 2021

Hi @gan gan ,

A fix for this issue is available to Server and Data Center customers in Confluence 7.4.10
Upgrade now or check out the Release Notes to see what other issues are resolved.

https://jira.atlassian.com/browse/CONFSERVER-67893

gan gan
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
October 25, 2021

我这边不方便进行升级,有没有什么缓解办法?

0 votes
Kishan Sharma
Community Champion
October 26, 2021

看起来这里唯一的选择是升级 Confluence,但我建议向 Atlassian Support 提出支持请求,以确认并了解是否还有其他解决方法。

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
TAGS
AUG Leaders

Atlassian Community Events