With respect to this vulnerability, do we have to run the mitigation script at all if we have "Allow people to sign up to create their account" turned off ?
My reading of the vulnerability would say no, but I would defer to Atlassian if they say something different. A lot of people have the same question on this ticket. I would add yourself as a watcher to see if Atlassian responds with confirmation.
Atlassian recommends running the workaround/mitigation script even if 'Allow people to sign up to create their own account' is disabled. There are several endpoints identified that expose Confluence to CVE-2021-26084, so applying the workaround script will temporarily mitigate against the known vulnerable end points until you can upgrade to a version that fixes this permanently.
We've reworded the advisory (Confluence Security Advisory CVE-2021-26084 - OGNL injection - 2021-08-25) to remove any ambiguity.
It looks like you're new here. Sign in or register to get started.