Dear Confluence Team,
We have just revealed a security issue on our Confluence server - someone was able to place the below command in the code:
Could you please advise what is the possible way this has been introduced?
The Confluence Server version we run is 7.7.2.
I would be grateful for a prompt response.
Kind regards,
Alicja Mostowik
I can see your confluence version is affected by CVE-2021-26084 - Confluence Server Webwork OGNL injection vulnerability. Please find the mitigation steps mentioned in the link.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Join us to learn how your team can stay fully engaged in meetings without worrying about writing everything down. Dive into Loom's newest feature, Loom AI for meetings, which automatically takes notes and tracks action items.
Register today!Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.