You're on your way to the next level! Join the Kudos program to earn points and save your progress.
Level 1: Seed
25 / 150 points
Next: Root
1 badge earned
Challenges come and go, but your rewards stay with you. Do more to earn more!
What goes around comes around! Share the love by gifting kudos to your peers.
Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!
Join now to unlock these features and more
The Atlassian Community can help you and your team get more value out of Atlassian products and practices.
We recently discovered that cVE-2020-13936 (Velocity-1.6.4) is in the latest stable version. We want to know if you have a plan to deal with this.
Confluence doesn't have "stable" versions, it has versions that are released because they work.
On top of that, the problem here is "This applies to applications that allow untrusted users to upload/modify velocity templates"
Confluence doesn't do that. It's code change (requiring root access to your Confluence server), or being sneaky in user macros (server only, and Confluence admins only).
As you have to trust your admins, with any software, this is not a problem. Untrusted users can't make any form of attack.
Hey @zhangyifei
A good check to see if a product is impacted by a CVE is to search JAC - eg: https://jira.atlassian.com/issues/?jql=text%20~%20%22CVE-2020-13936%22
It's no guarantee, but it is an indicator
CCM
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thanks @Nic Brough -Adaptavist-
Hi @zhangyifei
Upgrade the confluence version to latest stable release, if they do have CVE you mentioned that should be solved,
And FYI if any CVE are found for any Atlassian applications, team will notify customers to upgrade the server
Here's the release notes of latest stable version of confluence
https://confluence.atlassian.com/conf713/confluence-release-notes-1077914914.html
Thanks,
Pramodh
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.