When this Critical severity RCE (Remote Code Execution) vulnerability was introduced? If the versions of my instances were 5.x, 7.1.x, 7.4.x, what else can I do except upgrading to 8.x? Or am I be affected by CVE-2023-22527?
Hi @dearjane_fan
Please review the advisory we sent for CVE-2023-22527. It explicitly lists the impacted versions.
No versions prior to Confluence 8.0.0 are known to be impacted. The above listed versions should be fine, though I would note they're all impacted by other critical and high severity CVEs, and I would recommend upgrading to the latest Confluence 8.5.x LTS release if possible.
Thanks, James Ponting Engineering Manager - Confluence Data Center
As the CVE mentions "out of date" versions, I'd recommend upgrading to be safe. Is there a reason you don't want to do this?
Ste
Hi @dearjane_fan,
It's also worth saying that there are a significant number of functional improvements you will benefit from by upgrading Confluence:
Your 5.x upgrade is likely to involve the most effort as you will need to first move to 7.19.x:
Please see the following documentation to assist with your upgrade:
I hope that helps!
Charlie
@James Ponting Thanks a lot!
Lol. Cause managers always say we cannot upgrade due to kinds of unsolved problems. Instead of upgrading the whole app, they would rather use minimal operations such as patches. But thanks a lot @Ste Wright
it would be helpful. Thank you @Charlie Marriott
It looks like you're new here. Sign in or register to get started.