Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

I have a vulnerable version of confluence however im not sure how to check if i am exposed?

Jose Alvarez
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
April 26, 2019

We have version 5.2 and i think we are not exposed online however im not sure how or if i can scan to see if i have entry points exposed publicly?  Does anyone have a tool and or a way to check what is exposed on confluence??

thx

 

1 answer

0 votes
Brant Schroeder
Community Champion
April 26, 2019

Jose,

There is no out of the box Confluence specific vulnerability checker tool.  There are security tools like wireshark, metasploit, snort, etc. that you can use to check a wide variety of vulnerabilities and could be used for certain Confluence vulnerabilities.   you would however need to know how to use them and configure them.  If you have a security team/person they would be able to help you check for vulnerabilities on your Confluence instance.  

When Atlassian releases a security advisory like this one https://confluence.atlassian.com/doc/confluence-security-advisory-2019-04-17-968660855.html it provides all the information needed to fix the issue or mitigate it. 

If we apply this security advisory to your version 5.2 and you can not upgrade to fix the issue you need to review how to mitigate the issue.  The mitigation will usually prevent the exploit from being used but in turn you will in most cases lose functionality in your Confluence instance. If you have performed the mitigation and you have the results explained in the document then you know that the mitigation changes are in place.  If you want to do additional testing then you would have to have a firm understanding of how to exploit the vulnerability, validate that you can and then execute it after the change is in place.  Maybe your security team could help you with this.  

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events