CVE-2022-26134 and the fixed version

Patrick Opaco June 3, 2022

You mentioned in https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html that the fixed versions are:

  • 7.4.17

  • 7.13.7

  • 7.14.3

  • 7.15.2

  • 7.16.4

  • 7.17.4

  • 7.18.1

Where can i find version 7.16.4 in your release notes under https://confluence.atlassian.com/doc/confluence-release-notes-327.html?

1 answer

1 vote
Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
June 3, 2022

Hi Patrick,

The release notes for 7.16.4 are linked on that page, https://confluence.atlassian.com/doc/issues-resolved-in-7-16-4-1137639706.html

You can also find the downloads and release notes within the download archives page.

Patrick Opaco June 3, 2022

Also, just a clarifcation. The published fixed versions are as is where is:

  • 7.4.17

  • 7.13.7

  • 7.14.3

  • 7.15.2

  • 7.16.4

  • 7.17.4

  • 7.18.1

 

The reason why I'm asking is because we have already tested 7.16.3 in our non-prod last week so it means that if we proceed to 7.16.3 for production today, this version (7.16.3) won't fix the critical security issue that Confluence raised and instead we should at  least be at version 7.16.4. 

Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
June 3, 2022

Correct, 7.16.3 is still vulnerable.  Please upgrade to 7.16.4 in order to resolve this.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events