Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,366,849
Community Members
 
Community Events
168
Community Groups

CVE-2021-42574 Patches - when available for download ?

When will updates be available to download to address the CVE that was emailed out to all Atlassian product users?

In particular when will the next update to the current version 6.13.23 of Confluence Data Center Starter Edition be released to address this CVE?

Here is the Atlassian CVE if people missed it

https://confluence.atlassian.com/security/multiple-products-security-advisory-unrendered-unicode-bidirectional-override-characters-cve-2021-42574-1086419475.html

 

Thanks

4 comments

Does anyone know if the patches are for Atlassian products like Confluence, Jira etc, or for the mobile apps too that people get from the Play store and Apple store?

The announcement mentions "Jira and Confluence Server mobile apps" under "Products"

Then also "Marketplace app for Jira Service Management" under "Affected Versions".

 

From the description, it sounds like a server side patch. Is it also client side?

Bill Bailey Community Leader Nov 01, 2021

Since I am on the same version (6.13.23) as you, and saw the notice, I did some research. It seams that 6/13 went EOL when they released the LTS 7.13. Per the 6.13 release notes:

Update: We have extended the end of life date for Confluence 6.13. We'll continue to make 6.13.x bugfixes available until the release of the next LTS (around April - June 2021). This gives you the flexibility to upgrade to Confluence 7.4 LTS, or wait and upgrade to the latest LTS in 2021.

So this means they are not planning on releasing a fix, as our version went EOL in August.

We're currently running Jira & Confluence that are no longer covered under Atlassian support instances inside Docker containers Will there be any patches available to mitigate CVE-2021-42574 for these types of instances?

Like # people like this

Will a patch be available to fix the issue on JIRA/Confluence versions prior to the upgrade? A patch rather than a full upgrade would be very useful.

Like # people like this
Bill Bailey Community Leader Nov 02, 2021

There was no reference to a patch ever being available. The only option is to upgrade to a fixed version.

I agree, Jane. It seems silly that we have to go through the entire process of going to a completely new version to fix an issue that could very well be fixed with a simple patch.

This would mark the 2nd time in just over a week that I'm required to install a new version of Jira Service Management... and the workaround for the issue last week was simply deleting (or renaming) a file.

But considering Atlassian is discontinuing support for self-hosted server offerings, I'm going to guess that they won't go through the effort of putting together patches to make life easier for us. I am finding it peculiar that we're seeing more of these advisories lately, as they're trying to push people into their cloud offerings. I'm not trying to start any conspiracies but the timing of all these...

Like Eric Haskett likes this

Comment

Log in or Sign up to comment
TAGS

Atlassian Community Events