Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in
It's not the same without you

Join the community to find out what other Atlassian users are discussing, debating and creating.

Atlassian Community Hero Image Collage

CVE-2021-42574 Patches - when available for download ?

DEW Unix I'm New Here Nov 01, 2021

When will updates be available to download to address the CVE that was emailed out to all Atlassian product users?

In particular when will the next update to the current version 6.13.23 of Confluence Data Center Starter Edition be released to address this CVE?

Here is the Atlassian CVE if people missed it

https://confluence.atlassian.com/security/multiple-products-security-advisory-unrendered-unicode-bidirectional-override-characters-cve-2021-42574-1086419475.html

 

Thanks

4 comments

Does anyone know if the patches are for Atlassian products like Confluence, Jira etc, or for the mobile apps too that people get from the Play store and Apple store?

The announcement mentions "Jira and Confluence Server mobile apps" under "Products"

Then also "Marketplace app for Jira Service Management" under "Affected Versions".

 

From the description, it sounds like a server side patch. Is it also client side?

Bill Bailey Community Leader Nov 01, 2021

Since I am on the same version (6.13.23) as you, and saw the notice, I did some research. It seams that 6/13 went EOL when they released the LTS 7.13. Per the 6.13 release notes:

Update: We have extended the end of life date for Confluence 6.13. We'll continue to make 6.13.x bugfixes available until the release of the next LTS (around April - June 2021). This gives you the flexibility to upgrade to Confluence 7.4 LTS, or wait and upgrade to the latest LTS in 2021.

So this means they are not planning on releasing a fix, as our version went EOL in August.

We're currently running Jira & Confluence that are no longer covered under Atlassian support instances inside Docker containers Will there be any patches available to mitigate CVE-2021-42574 for these types of instances?

Like # people like this

Will a patch be available to fix the issue on JIRA/Confluence versions prior to the upgrade? A patch rather than a full upgrade would be very useful.

Like # people like this
Bill Bailey Community Leader Nov 02, 2021

There was no reference to a patch ever being available. The only option is to upgrade to a fixed version.

I agree, Jane. It seems silly that we have to go through the entire process of going to a completely new version to fix an issue that could very well be fixed with a simple patch.

This would mark the 2nd time in just over a week that I'm required to install a new version of Jira Service Management... and the workaround for the issue last week was simply deleting (or renaming) a file.

But considering Atlassian is discontinuing support for self-hosted server offerings, I'm going to guess that they won't go through the effort of putting together patches to make life easier for us. I am finding it peculiar that we're seeing more of these advisories lately, as they're trying to push people into their cloud offerings. I'm not trying to start any conspiracies but the timing of all these...

Like Eric Haskett likes this

Comment

Log in or Sign up to comment
TAGS
Community showcase
Published in Confluence Cloud

🏠 Say hello to the new Confluence Home!

Hi Atlassian Community, My name is DJ Chung, and I’m a Product Manager on the Confluence Cloud team. Today, I’m excited to share a new and improved version of Home. The new Home helps you ...

38,504 views 28 126
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you