How to deal with CVE-2021-26084

petrvokoun March 24, 2022

Hello,

we have bought a license for Confluence server, but since Atlassian ended the development of this product, we do not pay the maintenance anymore.

Recently, it has come to our knowledge that there is a critical security bug in your product, addressable as CVE-2021-26084, which could cause severe damage to our company.

It is not possible for us to upgrade to newer version not we want or can migrate to cloud due to our internal security protocols. 

We need an official statement how to deal with this problem, as soon as possible. We believe that security issues like this must be possible to fix even without paid maintenance, since without it your product cannot be used anymore. 

Thank you,

Kind Regards,

Petr Vokoun

1 answer

1 accepted

1 vote
Answer accepted
Fabio Racobaldo _Herzum_
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
March 24, 2022

Hi @petrvokoun ,

here an official statement provided by Atlassian https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html

If you can't upgrade your current Confluence , you can mitigate that issue through the workaround provided by Atlassian in that article.

Hope this helps,

Fabio

petrvokoun March 24, 2022

Hi Fabio,

we will try it asap. Thanks a lot!

Petr

Fabio Racobaldo _Herzum_
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
March 24, 2022

You're welcome @petrvokoun .

Please accept my answer so that this thread can be considered closed.

Like # people like this

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events