Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Possible false positive on AV scan in Confluence component?

Team Technologies
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
February 14, 2022

I run a server with Confluence installed on it, an installation that was completed on December the 30th. Today, my ClamAV antivirus scanner has come back with a hit for an infection ("Win.Exploit.Deepscan-9938899-0") in the file aspose-words-20.11-shaping-harfbuzz-plugin.jar in the directory /var/atlassian/application-data/confluence/plugins-osgi-cache/felix/felix-cache/bundle176/version0.0/document-conversion-library-2.4.2.jar-embedded/META-INF/lib/ - however it appears to have a time modified stamp of December the 30th at 16:43, when the installation was set up.

The MD5 checksum of this file is d4596742116142d2311739dab4155aa5 - is this a false positive or do I have a genuine infection here? Any chance someone else can md5sum this file and compare the checksum for me?

1 answer

1 accepted

0 votes
Answer accepted
Dean Norman
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
February 16, 2022

Hi @Team Technologies 

      I ran an md5sum of the file on a couple of confluence instances and the the checksum of the file matched yours:

/var/atlassian/application-data/confluence/plugins-osgi-cache/felix/felix-cache/bundle176/version0.0/document-conversion-library-2.4.2.jar-embedded/META-INF/lib# md5sum aspose-words-20.11-shaping-harfbuzz-plugin.jar

d4596742116142d2311739dab4155aa5  aspose-words-20.11-shaping-harfbuzz-plugin.jar

I hope that helps!

 

Best regards,

Dean

Team Technologies
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
February 16, 2022

Thanks for this - between that and some other things I've done (including the AV itself now not seeing it as an infection), I'm happy that this was a false positive. :)

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events