I'm hoping for clarity on CVE-2022-26134, we're running a fairly old version (5.10.2) still and wondered if that version was also impacted by this exploit? Our instances is not available to the general internet and is firewalled off locally on our network.
Hi Frank,
If the Confluence instance cannot be accessed from the general internet, the risk of an exploit/attack originating from there is negated.
However, out of an abundance of caution, the guidance on the Confluence Security Advisory page for CVE-2022-26134 still applies, even for these End of Life (EOL) versions.
Due to the critical nature of this vulnerability and the variety of ways in which instances can be accessed, please work with local network/security team(s) to determine if mitigation is needed.
Based on this it looks like you are affected:
All supported versions of Confluence Server and Data Center are affected.
Confluence Server and Data Center versions after 1.3.0 are affected.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.