Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Confluence not working after brach CVE-2019-3395

Eliran E
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
April 22, 2019

Hi,

 

So my server got breached after the last vulnerability you've released:

https://confluence.atlassian.com/doc/confluence-security-advisory-2019-03-20-966660264.html

 

it showed the same signs and everything.

After a long time cleaning up the server and ending the botnet usage on my server i am trying to lunch the confluence but am not able to.

it just isn't accessible, not from within the server nor outside.

 

i need your assistance here please,

please tell me how to proceed.

 

Best,

Eliran.

1 answer

1 vote
Daniel Eads
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
April 22, 2019

Hey Eliran,

I wrote an article with the most common payload we've seen and steps others have taken to clean up from the attack. You can read it here, and it links to additional resources that will be useful.

If after reading the article and going through the steps Confluence still isn't launching, here's what would be useful to know:

  1. Any processes running under the confluence user (the article talks about how to check this with the top command)
  2. Output in the Confluence application log - this is located in <confluence-home>/logs/atlassian-confluence.log - just the bits since the last time you tried to start Confluence would be helpful

Thanks, hoping to help get your instance back up and running soon!
Daniel | Atlassian Support

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events