Dear Confluence Team,
We have just revealed a security issue on our Confluence server - someone was able to place the below command in the code:
Could you please advise what is the possible way this has been introduced?
The Confluence Server version we run is 7.7.2.
I would be grateful for a prompt response.
Kind regards,
Alicja Mostowik
Hi @Alicja Mostowik
I can see your confluence version is affected by CVE-2021-26084 - Confluence Server Webwork OGNL injection vulnerability. Please find the mitigation steps mentioned in the link.
Thank you!
It looks like you're new here. Sign in or register to get started.