Need assistance with the three queries below:
1> For https://jira.atlassian.com/browse/CONFSERVER-74276
There are no fix versions in 7.15.x or 7.14.x. Should we consider them as vulnerable? Also the affected versions only mention 7.13.1, do we consider that version before 7.13.x like 7.4.x or 7.5.x are not vulnerable? We need clear understanding on which version ranges of Confluence are affected and which ones are not.
2> For https://jira.atlassian.com/browse/CONFSERVER-61266
Should we consider all versions before 7.11.0 as affected as mentioned in the description? For example, 7.10.x , 7.9.x ?
3> For https://confluence.atlassian.com/security/multiple-products-security-advisory-hazelcast-vulnerable-to-remote-code-execution-cve-2016-10750-1116292387.html?utm_source=alert-email&utm_medium=email&utm_campaign=bitbucket-data-center-confluence-data-center-security-advisory-march_EML-12770&jobid=105489999&subid=1544944158
Are Confluence Data center versions 7.5.x to 7.12.x affected?
@vishal bhaskar
1. Yes, you should upgrade. As the link states and version of Confluence 7.13.1 or below
2. Yes anything below 7.11.0
3. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.
It looks like you're new here. Sign in or register to get started.