Confluence has Vulnerabilities (detailed in Description section) - need your help.

MUFG ALM Team January 4, 2019

Confluence has below Vulnerabilities on application level, that needs a fix . We need to know which upgraded version will solve the vulnerabilities mentioned below.

We are on v5.9 (chwiktst201). Is it possible to skip v6 and upgrade directly to v7.x? Also. Please help us with upgrading the application.

Title

Server

#

Atlassian Confluence Server Cross Site Scripting (XSS) Vulnerability

chwiktst201

1

Atlassian Confluence Server Remote Code Execution Vulnerability

chwiktst201

2

Atlassian Hipchat Integration Plugin for Bitbucket Server, Jira, Confluence Secret Key Vulnerability

chwiktst201

1

Atlassian OAuth Plugin 'IconUriServlet' Server Side Request Forgery (SSRF) Vulnerability (OAUTH-344)

chwiktst201

1


Thank you.

Piyush Gaba <Piyush.Gaba@unionbank.com>

MUFG ALM Team

1 answer

0 votes
Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
January 4, 2019

There is no Confluence 7, you just want to jump to 6.high (probably 6.13 as the latest).  See https://confluence.atlassian.com/doc/upgrading-confluence-4578.html

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events