Does this workaround also applies to LTS 7.13.5 although only version >7.15 are mentioned?
Mitigation
If you are unable to upgrade Confluence immediately, then as a temporary workaround, you can mitigate the CVE-2022-26134 issue by updating the following files for the specific version of the product.
For Confluence 7.15.0 - 7.18.0
If you run Confluence in a cluster, you will need to repeat this process on each node. You don't need to shut down the whole cluster to apply this mitigation.
Shut down Confluence.
Download the following 1 file to the Confluence server:
Delete (or move the following JAR outside of the Confluence install directory):
<confluence-install>/confluence/WEB-INF/lib/xwork-1.0.3-atlassian-8.jar
Do not leave a copy of this old JAR in the directory.
Copy the downloaded xwork-1.0.3-atlassian-10.jar into <span><confluence-install>/confluence/WEB-INF/lib/<br> </span>
Check the permissions and ownership on the new xwork-1.0.3-atlassian-10.jar file matches the existing files in the same directory.
Start Confluence.