I follow this security advisory, and update confluence by mitigation.
CVE-advisory
I found my confluence instance still hacked by (kdevtmpfsi kinsing)
Confluence End Of Life versions are not fully tested with the workaround???
This is true?
The mitigation steps have been tested for 6.0.0 and higher versions. However there are different mitigation steps for 7.15.0 and higher versions when compared to 7.14.2 and lower versions. The older versions require additional mitigation steps when compared to the more recent versions.
Is it possible that you might have followed the steps for 7.15.0 and higher versions instead of the 6.0.0-7.14.2 mitigation steps?
Hi @hongjiangli ,
as Confluence has published in it's Advisory, that's true.
https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html
And that is, what End Of Life means, Atlassian does not support that versions any more. If you want to get Fixes / Support, you need to be running a supported version of the applications.
Hi,Andy
I find steps for 7.15.0 and higher versions include 6.0.0-7.14.2 mitigation steps.
the difference is one patch file:
xwork-1.0.3-atlassian-10.jar
and three patch files
webwork-2.1.5-atlassian-4.jar
CachedConfigurationProvider.class
thanks,
license is EOL,we just want to fix
Yes the workaround for older versions has additional steps, is what I was trying to point out. The mitigation steps though are only intended to prevent being exploited by that specific CVE until you can upgrade.
There are also two other additional security advisories out there that affect 7.1.1, please see:
Being that there are other known CVEs for that version, and that version is EOL as well, it is possible that you could be getting exploited by a different CVE entirely here.
Because of that, I would recommend that you upgrade to a supported version such as 7.13.7 that contains fixes for all of these CVEs. You can renew a previous server license by going to https://my.atlassian.com or creating an evaluation license there that will work for 30 days, which should be long enough to complete the upgrade at least.
Andy
"Because of that, I would recommend that you upgrade to a supported version such as 7.13.7 that contains fixes for all of these CVEs. You can renew a previous server license by going to https://my.atlassian.com or creating an evaluation license there that will work for 30 days, which should be long enough to complete the upgrade at least."
-- If I create an evaluation license and upgrade to 7.13.7, after 30 days, can I still use old license to support basic service?Of course, I would like to upgrade, I afraid the service would stop if I do not renew license after upgrade.
Thanks
LEON
It looks like you're new here. Sign in or register to get started.