Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in
Celebration

Earn badges and make progress

You're on your way to the next level! Join the Kudos program to earn points and save your progress.

Deleted user Avatar
Deleted user

Level 1: Seed

25 / 150 points

Next: Root

Avatar

1 badge earned

Collect

Participate in fun challenges

Challenges come and go, but your rewards stay with you. Do more to earn more!

Challenges
Coins

Gift kudos to your peers

What goes around comes around! Share the love by gifting kudos to your peers.

Recognition
Ribbon

Rise up in the ranks

Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!

Leaderboard

Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,641,786
Community Members
 
Community Events
196
Community Groups

CVE-2021-42574 Patches - when available for download ?

When will updates be available to download to address the CVE that was emailed out to all Atlassian product users?

In particular when will the next update to the current version 6.13.23 of Confluence Data Center Starter Edition be released to address this CVE?

Here is the Atlassian CVE if people missed it

https://confluence.atlassian.com/security/multiple-products-security-advisory-unrendered-unicode-bidirectional-override-characters-cve-2021-42574-1086419475.html

 

Thanks

4 comments

Does anyone know if the patches are for Atlassian products like Confluence, Jira etc, or for the mobile apps too that people get from the Play store and Apple store?

The announcement mentions "Jira and Confluence Server mobile apps" under "Products"

Then also "Marketplace app for Jira Service Management" under "Affected Versions".

 

From the description, it sounds like a server side patch. Is it also client side?

Bill Bailey
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
Nov 01, 2021

Since I am on the same version (6.13.23) as you, and saw the notice, I did some research. It seams that 6/13 went EOL when they released the LTS 7.13. Per the 6.13 release notes:

Update: We have extended the end of life date for Confluence 6.13. We'll continue to make 6.13.x bugfixes available until the release of the next LTS (around April - June 2021). This gives you the flexibility to upgrade to Confluence 7.4 LTS, or wait and upgrade to the latest LTS in 2021.

So this means they are not planning on releasing a fix, as our version went EOL in August.

We're currently running Jira & Confluence that are no longer covered under Atlassian support instances inside Docker containers Will there be any patches available to mitigate CVE-2021-42574 for these types of instances?

Like # people like this

Will a patch be available to fix the issue on JIRA/Confluence versions prior to the upgrade? A patch rather than a full upgrade would be very useful.

Like # people like this
Bill Bailey
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
Nov 02, 2021

There was no reference to a patch ever being available. The only option is to upgrade to a fixed version.

I agree, Jane. It seems silly that we have to go through the entire process of going to a completely new version to fix an issue that could very well be fixed with a simple patch.

This would mark the 2nd time in just over a week that I'm required to install a new version of Jira Service Management... and the workaround for the issue last week was simply deleting (or renaming) a file.

But considering Atlassian is discontinuing support for self-hosted server offerings, I'm going to guess that they won't go through the effort of putting together patches to make life easier for us. I am finding it peculiar that we're seeing more of these advisories lately, as they're trying to push people into their cloud offerings. I'm not trying to start any conspiracies but the timing of all these...

Like Eric Haskett likes this

Comment

Log in or Sign up to comment
TAGS
AUG Leaders

Atlassian Community Events