We are running Confluence on a VM using Docker image atlassian/confluence-server:7.5.0 - image ID 7e67fc285c1b and we are no longer covered under Atlassian's support. Do I have any path in mitigating the security vulnerability described in CVE-2021-26084 without purchasing new support coverage from Atlassian?
Since I have the Confluence INSTALLATION_DIRECTORY mounted to a volume, I pointed the cve-2021-26084-update.sh script to that directory and ran it. The script successfully ran and I restarted Confluence. Seems kind of awkward and I'll have to remember to run again if I have to rebuild the volume. But at least the patch appears applied.
Hi @Bob Calder thanks for sharing, you have already got it working. Similar case was discussed here with a solution, you can refer to it.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.