I've just performed an upgrade to Confluence 3.5.16.
Plugin Manager claims that WebDAV plugin has updates available.
Clicking Update results in a red error with the message "Problem accessing plugin file at https://marketplace.atlassian.com/download/plugins/confluence.extra.webdav/version/3?from=upm."
Is it safe to use WebDAV 2.5.1 on Confluence 3.5.16? The recent Critical XML Parsing Vulnerability Security Alert clearly states that WebDAV should be disabled on lower versions of Confluence, but it's not clear if this combination would now safe that Confluence is updated.
Hi MatrixPlasm,
I got a response from Atlassian regarding the "available upgrade" for WebDAV plugin:
I would suggest to stick with the bundled version, as I am afraid it would not be compatible as well. I believe the fix was already applied in Confluence 3.5.16 without needing to update the plugin. So sticking to the current version would be the best action now.
By the way, the alert for WebDAV plugin has dissapeared from the "Available updates" section on Manage Plugins page in our Confluence (the available version 1.0-dr3 is still shown in WebDAV plugin details).
Regards,
Anna
Same error for our instance after upgrading from 3.5.13 to 3.5.16
WebDAV Plugin 2.5.1Plugin key: confluence.extra.webdavAvailable plugin version: 1.0-dr3Plugin system version: ONELicense: BSD
Hey Sam, MatrixPlasm,
Did you find any reply? Should the WebDAV plugin be upgraded from 2.5.1 after Confluence upgrade to 3.5.16?
Basic testing showed that WebDAV 2.5.1 is still working with Confluence 3.5.16...
BR,
Hey Anna,
No reply... still shows in Manage Plugins (even after a service restart and recent UPM update to 2.3.0). It does appear to still be working fine, but kind of annoying to have a plugin say that is has an updated version (maybe even one that addresses an XML vulnerability - no notes to confirm that though), yet you can't download or install it anywhere (haven't even found elsewhere to manually download and upload).
The other weird thing is using the URL in the error "https://marketplace.atlassian.com/download/plugins/confluence.extra.webdav/version/3?from=upm" redirects to download "webdav-plugin-1.0-dr3.jar" (which of course doesn't exist in their builds on their support page - https://studio.plugins.atlassian.com/wiki/display/WBDV/Confluence+WebDAV+Plugin) especially as an "upgrade to v2.5.1!?
I created a Bug regarding this issue... see if anything comes of it:https://studio.plugins.atlassian.com/browse/WBDV-239
MatrixPlasm,
Thanks for reply. We have a similar issue also with the OfficeConnector plugin, which was upgraded automatically during the Confluence upgrade to some strange version "2.1.13-backport", which appeared to be incompatible with Confluence 3.5.16, so we replaced it manually with the version 1.18.
OfficeConnector 2.1.13-backport version is also not in the 'available versions' list on the OfficeConnector page https://marketplace.atlassian.com/221. I have raised a support request to Atlassian to clarify this issue. Will put an update here if I get any information.
Regards, Anna.
Interesting, hadn't noticed the "2.1.3-backport" until you mentioned it, ours is the same version, but appears to be working so far. I tried downloading and manually uploading 1.18 but it did not replace 2.1.3 (tried disabling and uploading too, no change).
Per Phillip Cher "The problem was at the documentation"... https://studio.plugins.atlassian.com/browse/WBDV-239 has been resolved and the update no longer shows up.
Hi all,
We are tracking the Java Script issue with the Office Connector in this bug report: https://jira.atlassian.com/browse/OFFCONN-89
Please watch/vote/comment on the issue so that our developers are informed of the issue and it's impact.
All the best,John
It looks like you're new here. Sign in or register to get started.