Running Confluence 5.2.3 on a win2003x86 server.
A huge security hole has been discussed : http://arstechnica.com/security/2014/04/critical-crypto-bug-in-openssl-opens-two-thirds-of-the-web-to-eavesdropping/
I am rather certain that the tomcat bundled with confluence is vulnerable.
a) Where is a version of tomcat that is patched?
b) How to install the patch in a running Win2003x86 server?
thank you!
I belive your question is related to the Heartbleed bug and how it is affecting Atlassian applications. This has been confirmed, after investigations, to be an infrastructure issue. Our findings have been published to this blog that outlines the issue context, please take some time to review the details here:http://blogs.atlassian.com/2014/04/openssl-cve-2014-0160-atlassian<br< a="">>To find out whether you are affected or not, please check the version of OpenSSL that is running on your server. OpenSSL 1.0.1 or 1.0.2 releases may be affected. The entirety of OpenSSLs statement regarding this matter can be accessed after this link:https://www.openssl.org/news/secadv_20140407.txt<br< a="">>Cheers
note, url above is bad. correct url is:
http://blogs.atlassian.com/2014/04/openssl-cve-2014-0160-atlassian/
Wait a minute. That blog:
Says to me: "The only reason you, the customer, have tomcat and openssl is because the confluence installer installed them. Yes, you now have an SSL cert on there. To patch up the openssl bug, that sits on your server because we gave it to you, you are on your own. Go figure it out."
What kind of support is that?
Um, not quite. Yes, you have the Tomcat they've supplied, but it uses the OpenSSL that you installed on your server.
Just looking at the two installs I've got at home - one is vulnerable (well, was...), the other is not affected. Both installed from the same file from Atlassian, both SSL enabled, but on different operating systems.
It looks like you're new here. Sign in or register to get started.