Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,298,226
Community Members
 
Community Events
165
Community Groups

Hi.

Considering to upgrade the onsite server version of Confluence to version 7.13.5 (long term).  I am however not sure if this security issue is fixed in this version.

Does anyone know if this version includes a fix for this security issue?

Thanks!

1 answer

1 accepted

0 votes
Answer accepted

Hi @Frode Aasegaard 
I hope you are well.

Confluence on any version is vulnerable to CVE-2022-22965 on very specific conditions:

All the following pre-conditions must be met for successful exploitation:

  • The product is running on JDK 9 or higher,

  • An attacker tricks a user into making a malicious HTTP request,

  • The request contains a valid Cross-Site Request Forgery token (note that the same-origin policy prevents an attacker from obtaining a user’s valid token),

  • The targeted user is logged into the application with ‘system administrator’ privileges.

  • Jira and Confluence only: The targeted user also has an active ‘secure administrator session’ (note that these sessions only last for 10 minutes by default).

 

The suggested workaround to mitigate possible problems is as follows

Customers with impacted on-premises products can downgrade from running JDK 9 or higher to JDK 8 or lower. This will eliminate the possibility of exploitation. These instructions can be used for changing the version of Java for Jira and Confluence:

 

 

For further information about this CVE, please check https://confluence.atlassian.com/kb/faq-for-cve-2022-22963-cve-2022-22965-1115149136.html .

 

Kind regards,
Thiago Masutti

Suggest an answer

Log in or Sign up to answer
TAGS
Community showcase
Published in Confluence

An update on Confluence Cloud customer feedback – June 2022

Hi everyone, We’re always looking at how to improve Confluence and customer feedback plays an important role in making sure we're investing in the areas that will bring the most value to the most c...

161 views 1 3
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you