I am trying to run the patch as directed via the security alert https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html
I am on Centos 7.9. I have followed the steps in the notice to run the patch script, but I keep getting permission denied. Is there some step that is missing, or is the script being expected to run from within a specific directory?
A couple of questions...
1. Did you set the INSTALLATION_DIRECTORY variable inside the script to the root directory where Confluence is installed?
2. Are you running the script as the owner of that directory?
Yeah, it was #2. I misread this instruction:
Change to the Linux user that owns the files in the Confluence Installation directory, for example
As being the user running confluence, not owning the files. Doh!
So the patch runs. Hopefully I can no get time to upgrade. F'ing hackers!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Bill Bailey
it sounds you are on the right path - probably the patch was applied already meanwhile.
Adding to what I could see in the Community the last days it might be needed to assess if a hacker already exploited the vulnerability.
If so, restoring the server from a backup proven not being hacked might make absolutetely sense.
Reading what the malware is capable of there are signs it tends to "come back" (leaving some backdoors). The specific 'miner' is also reported to make connections to other systems via SSH connections - in case there is ANY sign of hack it might be needed to check connected systems, too.
Hopefully it is not the case and the mitigation script alongside with an upgrade long-term is everything that was needed for your case.
Regards,
Daniel
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.