Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Does this notice(Confluence Security Advisory-2021-08-25) apply to version 3.5.2 or excluded?

Sueyon KO
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
September 13, 2021 edited
Hello.
I have seen this notice and have a question.

Confluence Security Advisory - 2021-08-25
Confluence Server and Data Center - CVE-2021-26084 - Confluence Server Webwork OGNL injection
https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html
I am using Atlassian Confluence 3.5.2, the Enterprise Wiki. Will this notice be included in the Affected versions as well as version 3.5.2?
Or is version 3.5.2 excluded from Affected versions?

I wonder if I should patch version 3.5.2  or not.
Thank you in advance.
Best Regards,
Sueyon KO

1 answer

1 accepted

0 votes
Answer accepted
Robert Wen_Cprime_
Community Champion
September 13, 2021

The notice doesn't apply to 3.5.2 only because it's well past its End of Life (EOL) date.

You may want to look at upgrading Confluence.  Be warned, though, you'll probably have to do some intermediate upgrades to get to the most current version (7.13)

Kishan Sharma
Community Champion
September 14, 2021

That's true, its very old version. I would suggest raising support ticket with Atlassian for further recommendations.

Sueyon KO
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
September 28, 2021

Thanks for your comment. I would consider to upgrade with the most current version as soon as possible.  Have a great day! 

Like • Kishan Sharma likes this

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events