Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Request for help to resolve vulnerabilities detected in Confluence

Lilia Gonzàlez April 26, 2019

Please estimate your help indicating the actions to follow to resolve the security news reported in the Confluence Vulnerability Analysis report (Reporte_acunetix_Confluence.pdf), attached in this request. As you can see, a high vulnerability and 205 medium state were detected.

Thank you for your prompt cooperation

1 answer

0 votes
Diego
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
April 29, 2019

Hello there!

Lilia, we received no PDF file with your question. With this in mind, we suggest that you upload it somewhere and send a download link our way. Please, keep in mind that everyone can access the content shared here. So take care not share access to private and / or sensitive content with this shared link.

Since your question comes to tackle vulnerabilities, I would like to warn you that pretty recently we had two CVEs, which are explained here:

Confluence Security Advisory - 2019-03-20 | March 2019 Confluence Server Advisory - WebDAV and Widget Connector vulnerabilities

Confluence Security Advisory - 2019-04-17 | Confluence - Path traversal vulnerability - CVE-2019-3398

 

For both CVEs, we strongly advise you to upgrade Confluence if you are running one of the affected versions. The latest CVE shows us that Confluence 6.15.2 is safe from both exploits.

Looking forward to your reply Lilia!

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events