Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

CVE-2022-26134 for older versions (5.10.2)

Frank Warta June 3, 2022

I'm hoping for clarity on CVE-2022-26134, we're running a fairly old version (5.10.2) still and wondered if that version was also impacted by this exploit? Our instances is not available to the general internet and is firewalled off locally on our network.

2 answers

1 accepted

5 votes
Answer accepted
Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
June 3, 2022

Hi Frank,

If the Confluence instance cannot be accessed from the general internet, the risk of an exploit/attack originating from there is negated.

However, out of an abundance of caution, the guidance on the Confluence Security Advisory page for CVE-2022-26134 still applies, even for these End of Life (EOL) versions.

Due to the critical nature of this vulnerability and the variety of ways in which instances can be accessed, please work with local network/security team(s) to determine if mitigation is needed.

2 votes
John McCarthy June 3, 2022

Based on this it looks like you are affected:

  • All supported versions of Confluence Server and Data Center are affected.

  • Confluence Server and Data Center versions after 1.3.0 are affected.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events