Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Confluence Security Advisory 2022-06-02

Muhammad Nafees June 3, 2022

Today we received a notification regarding Conference Security I want to know what we need to do regarding this Security issue because we are using Confluence cloud services which are managed by Jira.

we don’t have our own hosted services of confluence. So please guide me regarding this email.

1 answer

1 accepted

2 votes
Answer accepted
Alex Koxaras _Relational_
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
June 3, 2022

Hi @Muhammad Nafees and welcome to the community!

The official announcement states that Confluence cloud is NOT affected by this vulnerability. So you don't have to do anything.

Atlassian Cloud sites are protected

If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable. Our investigations have not found any evidence of exploitation of Atlassian Cloud.

 

Hope that helps!
Alex

Muhammad Nafees June 3, 2022

thanks @Alex Koxaras _Relational_ for your quick response :)

Alex Koxaras _Relational_
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
June 3, 2022

No worries!
Kindly mark my answer as accepted, to help others.

Cheers!

Shawn McAtee June 3, 2022

Hi @Alex Koxaras _Relational_ My org is on server version. Our Atalssian products are on a VPN, and authentication is required to reach the product. I did not see any mention of VPN hosted products being excluded from this vulnerability, so my assumption is that we are at risk. I just want to confirm that my statement is accurate. If VPN authentication is required to access our product, and none of our stack is front facing or exposed to the internet, would our system still be considered to be in a “critical” state?

Alex Koxaras _Relational_
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
June 3, 2022

Hi @Shawn McAtee ,

Unfortunately I am not eligible to answer this question with an official answer. I'm not part of the Atlassian team, but I am working with a solution partner. With our customers we left no exception. We notified everyone, those whose instance was exposed, but also behind a firewall or a vpn. If you were a client of mine, I would suggest that you also take actions against this. Keep in mind that Atlassian stated that most likely by the end of the day (PDT) they will have provide a fix.

Like # people like this

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
STANDARD
TAGS
AUG Leaders

Atlassian Community Events