Hi all,
Recently Atlassian has announced a critical Confluence vulnerability.
https://confluence.atlassian.com/doc/confluence-security-advisory-2019-03-20-966660264.html
Of course the best way to fix the issue should be updating Confluence to the fixed version.
However, currently we don't have enough time to thoroughly test our custom plugins with the new version.
And Atlassian's mitigation plan to disable WebDAV plugin may not be acceptable, as we regularly use the Office Connector feature.
Hence we started to find another mitigation, and are wondering if the following would work or not. The idea is, as we are running Confluence behind a Apache reverse proxy, we added the followings to the Apache settings.
RewriteEngine On
RewriteCond %{REQUEST_URI} ^/confluence/.*$
RewriteCond %{REQUEST_METHOD} ^(PROPFIND|PROPPATCH|MKCOL|COPY|MOVE|LOCK|UNLOCK)
RewriteRule .* - [R=405,L]
This simply blocks all the WebDAV methods and returns a Method Not Allowed error.
Hope to hear from you if our approach looks good or not.
BR,
Toshio