CVE-2021-42574 Patches - when available for download ?

DEW Unix November 1, 2021

When will updates be available to download to address the CVE that was emailed out to all Atlassian product users?

In particular when will the next update to the current version 6.13.23 of Confluence Data Center Starter Edition be released to address this CVE?

Here is the Atlassian CVE if people missed it

https://confluence.atlassian.com/security/multiple-products-security-advisory-unrendered-unicode-bidirectional-override-characters-cve-2021-42574-1086419475.html

 

Thanks

4 comments

Stephan Hughson November 1, 2021

Does anyone know if the patches are for Atlassian products like Confluence, Jira etc, or for the mobile apps too that people get from the Play store and Apple store?

The announcement mentions "Jira and Confluence Server mobile apps" under "Products"

Then also "Marketplace app for Jira Service Management" under "Affected Versions".

 

From the description, it sounds like a server side patch. Is it also client side?

Bill Bailey
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
November 1, 2021

Since I am on the same version (6.13.23) as you, and saw the notice, I did some research. It seams that 6/13 went EOL when they released the LTS 7.13. Per the 6.13 release notes:

Update: We have extended the end of life date for Confluence 6.13. We'll continue to make 6.13.x bugfixes available until the release of the next LTS (around April - June 2021). This gives you the flexibility to upgrade to Confluence 7.4 LTS, or wait and upgrade to the latest LTS in 2021.

So this means they are not planning on releasing a fix, as our version went EOL in August.

Bob Calder November 2, 2021

We're currently running Jira & Confluence that are no longer covered under Atlassian support instances inside Docker containers Will there be any patches available to mitigate CVE-2021-42574 for these types of instances?

Like # people like this
Jane Simmons November 2, 2021

Will a patch be available to fix the issue on JIRA/Confluence versions prior to the upgrade? A patch rather than a full upgrade would be very useful.

Like # people like this
Bill Bailey
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
November 2, 2021

There was no reference to a patch ever being available. The only option is to upgrade to a fixed version.

Tom Shaffer November 2, 2021

I agree, Jane. It seems silly that we have to go through the entire process of going to a completely new version to fix an issue that could very well be fixed with a simple patch.

This would mark the 2nd time in just over a week that I'm required to install a new version of Jira Service Management... and the workaround for the issue last week was simply deleting (or renaming) a file.

But considering Atlassian is discontinuing support for self-hosted server offerings, I'm going to guess that they won't go through the effort of putting together patches to make life easier for us. I am finding it peculiar that we're seeing more of these advisories lately, as they're trying to push people into their cloud offerings. I'm not trying to start any conspiracies but the timing of all these...

Like Eric Haskett likes this

Comment

Log in or Sign up to comment
TAGS
AUG Leaders

Atlassian Community Events