Confluence doesn't have "stable" versions, it has versions that are released because they work.
On top of that, the problem here is "This applies to applications that allow untrusted users to upload/modify velocity templates"
Confluence doesn't do that. It's code change (requiring root access to your Confluence server), or being sneaky in user macros (server only, and Confluence admins only).
As you have to trust your admins, with any software, this is not a problem. Untrusted users can't make any form of attack.
Hey @zhangyifei
A good check to see if a product is impacted by a CVE is to search JAC - eg: https://jira.atlassian.com/issues/?jql=text%20~%20%22CVE-2020-13936%22
It's no guarantee, but it is an indicator
CCM
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thanks @Nic Brough -Adaptavist-
Hi @zhangyifei
Upgrade the confluence version to latest stable release, if they do have CVE you mentioned that should be solved,
And FYI if any CVE are found for any Atlassian applications, team will notify customers to upgrade the server
Here's the release notes of latest stable version of confluence
https://confluence.atlassian.com/conf713/confluence-release-notes-1077914914.html
Thanks,
Pramodh
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.