Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

How to deal with CVE-2021-26084

petrvokoun March 24, 2022 edited

Hello,

we have bought a license for Confluence server, but since Atlassian ended the development of this product, we do not pay the maintenance anymore.

Recently, it has come to our knowledge that there is a critical security bug in your product, addressable as CVE-2021-26084, which could cause severe damage to our company.

It is not possible for us to upgrade to newer version not we want or can migrate to cloud due to our internal security protocols. 

We need an official statement how to deal with this problem, as soon as possible. We believe that security issues like this must be possible to fix even without paid maintenance, since without it your product cannot be used anymore. 

Thank you,

Kind Regards,

Petr Vokoun

1 answer

1 accepted

1 vote
Answer accepted
Fabio Racobaldo _Herzum_
Community Champion
March 24, 2022

Hi @petrvokoun ,

here an official statement provided by Atlassian https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html

If you can't upgrade your current Confluence , you can mitigate that issue through the workaround provided by Atlassian in that article.

Hope this helps,

Fabio

petrvokoun March 24, 2022

Hi Fabio,

we will try it asap. Thanks a lot!

Petr

Fabio Racobaldo _Herzum_
Community Champion
March 24, 2022

You're welcome @petrvokoun .

Please accept my answer so that this thread can be considered closed.

Like • 2 people like this

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events