Our confluence's version 7.13.7, And our security team found a issue which name is CVE-2021-34429, And We want to know: Do you have a plan to fix CVE-2021-34429
Hi @guowu Hu
I not able to follow where it comes from the security department assumes CVE-2021-34429 would be affecting your installation - is there more information you could provide to understand that better?
Regards,
Daniel
Hi @guowu Hu ,
welcome to the Atlassian community!
Confluence 7.13.7 is not impacted by CVE-2021-34429. Based on this article I upgraded a customer instance to 7.13.7 and issue has been fixed.
If you go to the Troubleshooting and support tool (on the admin section) you will se that 7.13.7 security check is ok.
Hope this helps,
Fabio
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Fabio Racobaldo _Herzum_ , Thanks for your reply, But I has some questions.
1、I check the article what you provide , https://www.cve.org/CVERecord?id=CVE-2022-26134 , It show CVE-2022-26134, Do you mean you fix CVE-2022-26134 then CVE-2021-34429 will fixed too?
2、You said that confluence 7.13.7 is not impacted by CVE-2021-34429, But our security team scan confluence and got the issue which include CVE-2021-34429, I don't know why. Our confluence was recently upgraded from 7.13.2 to 7.13.7, Is the history file left after the upgrade causing the scan result to be abnormal?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.