We have a public-facing support site running confluence:
We recently received an anonymous email that contained otherwise internal information about our server:
While none of this information is particularly sensitive, how on earth would they be able to get it? Are they really able to execute any script on the server or is this somehow fake?
There has been a couple of Security Advisories that has been sent out regarding critical security vulnerabilities, so please make sure that you have the latest version of Confluence running. You can see all the advisories here.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.