Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,294,648
Community Members
 
Community Events
165
Community Groups

How to fix the vulnerability CVE-2020-29444

I need to fix the vulnerability, CVE-2020-29444 in Confluence server and Data center. I am not able to find any articles related to this. I need to know the information on the affected versions, fixed version etc.

3 answers

1 vote
Alex Koxaras Community Leader Jun 10, 2022

Hi @Shraddha Sudheendra and welcome to the community!

From what I read you had to upgrade the version of Confluence. According to this https://jira.atlassian.com/browse/CONFSERVER-61266?jql=labels%20%3D%20CVE-2020-29444 your version is most likely affected.

You could also try to upgrade the Team Calendar as it is stated here https://confluence.atlassian.com/teamcal/team-calendars-7-0-16-release-notes-1050549224.html

Hi @Shraddha Sudheendra ,

welcome to the Atlassian community!

As specified here https://jira.atlassian.com/browse/CONFSERVER-61266 :

 

Affected versions of Team Calendar in Confluence Server allow attackers to inject arbitrary HTML or Javascript via a Cross Site Scripting vulnerability in admin global setting parameters.

Affected versions:

  • < 7.11.0

Fixed version:

  • 7.11.0

Hope this helps,

Fabio

Andy Heinzer Atlassian Team Jun 10, 2022

I recommend upgrading to a 7.13.x version as it will contain the fix for https://jira.atlassian.com/browse/CONFSERVER-61266

But more specifically, upgrade to 7.13.7 as this also contains the fix for the more recent Advisory.  Plus this version is part of our Long term support releases, which ensures this minor version will continue to receive critical fixes throughout its supported term.

Like # people like this
0 votes
Steven Schouppe Community Leader Jun 10, 2022

Hi @Shraddha Sudheendra ,

Welcome!

As suggested here already, you should be OK if you're on the most recent LTS (= 7.13.7 today) and update Teams Calendar along with it.

LTS 7.13.7 will also introduce a fix for CVE-2022-26134.

Cheers,
Steven

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
VERSION
7.4.11
TAGS
Community showcase
Published in Confluence

Confluence: Where work and wellness meet

Feeling overwhelmed by the demands of work and life? With a 25% increase in the prevalence of anxiety and depression worldwide during the pandemic, for most of us, it’s a resounding yes . 🙋‍♀️ ...

815 views 8 21
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you