Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Does iText vulnerability affect Confluence (CVE-2017-9096)

mjb2kmn November 7, 2017

I am having difficulty finding what version of iText library is used in Confluence and even which versions of iText are vulnerable is not very clear.  

Does anyone have more information on whether or not Confluence is affected by the vulnerability? Or where I can see what version of iText a particular version of Confluence is using?

 

Security Advisory

1 answer

0 votes
Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
November 7, 2017

I suspect Confluence is using a version bundled inside some of it's internal add-ons, so the only way to know would be to read the code or un-bundle the add-ons and look for it.

However, my Confluence does refer to it, and I suspect is therefore using 2.1.7

confluence# find . -type f | grep -i itext
./licenses/com.lowagie--itext--2.1.7.txt

mjb2kmn November 10, 2017

That's about the same thing I found, I was hoping to be able to find it for other versions without searching each one.

I guess I'll just have to trust that Atlassian will be on top of this and notify customers if there is a vulnerability.

Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
November 10, 2017

They do actively check this stuff and alert us.  Solution Partners usually get an earlier mention if they are starting to think they might be affected.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events