I run a server with Confluence installed on it, an installation that was completed on December the 30th. Today, my ClamAV antivirus scanner has come back with a hit for an infection ("Win.Exploit.Deepscan-9938899-0") in the file aspose-words-20.11-shaping-harfbuzz-plugin.jar in the directory /var/atlassian/application-data/confluence/plugins-osgi-cache/felix/felix-cache/bundle176/version0.0/document-conversion-library-2.4.2.jar-embedded/META-INF/lib/ - however it appears to have a time modified stamp of December the 30th at 16:43, when the installation was set up.
The MD5 checksum of this file is d4596742116142d2311739dab4155aa5 - is this a false positive or do I have a genuine infection here? Any chance someone else can md5sum this file and compare the checksum for me?
I ran an md5sum of the file on a couple of confluence instances and the the checksum of the file matched yours:
/var/atlassian/application-data/confluence/plugins-osgi-cache/felix/felix-cache/bundle176/version0.0/document-conversion-library-2.4.2.jar-embedded/META-INF/lib# md5sum aspose-words-20.11-shaping-harfbuzz-plugin.jar
d4596742116142d2311739dab4155aa5 aspose-words-20.11-shaping-harfbuzz-plugin.jar
I hope that helps!
Best regards,
Dean
Thanks for this - between that and some other things I've done (including the AV itself now not seeing it as an infection), I'm happy that this was a false positive. :)
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.