The Atlassian Community can help you and your team get more value out of Atlassian products and practices.
I'm hoping for clarity on CVE-2022-26134, we're running a fairly old version (5.10.2) still and wondered if that version was also impacted by this exploit? Our instances is not available to the general internet and is firewalled off locally on our network.
Hi Frank,
If the Confluence instance cannot be accessed from the general internet, the risk of an exploit/attack originating from there is negated.
However, out of an abundance of caution, the guidance on the Confluence Security Advisory page for CVE-2022-26134 still applies, even for these End of Life (EOL) versions.
Due to the critical nature of this vulnerability and the variety of ways in which instances can be accessed, please work with local network/security team(s) to determine if mitigation is needed.
Based on this it looks like you are affected:
All supported versions of Confluence Server and Data Center are affected.
Confluence Server and Data Center versions after 1.3.0 are affected.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Feeling overwhelmed by the demands of work and life? With a 25% increase in the prevalence of anxiety and depression worldwide during the pandemic, for most of us, it’s a resounding yes . 🙋♀️ ...
Connect with like-minded Atlassian users at free events near you!
Find an eventConnect with like-minded Atlassian users at free events near you!
Unfortunately there are no Community Events near you at the moment.
Host an eventYou're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.