Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in
Celebration

Earn badges and make progress

You're on your way to the next level! Join the Kudos program to earn points and save your progress.

Deleted user Avatar
Deleted user

Level 1: Seed

25 / 150 points

Next: Root

Avatar

1 badge earned

Collect

Participate in fun challenges

Challenges come and go, but your rewards stay with you. Do more to earn more!

Challenges
Coins

Gift kudos to your peers

What goes around comes around! Share the love by gifting kudos to your peers.

Recognition
Ribbon

Rise up in the ranks

Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!

Leaderboard

How to fix the vulnerability CVE-2020-29444

I need to fix the vulnerability, CVE-2020-29444 in Confluence server and Data center. I am not able to find any articles related to this. I need to know the information on the affected versions, fixed version etc.

3 answers

1 accepted

1 vote
Answer accepted
Fabio Racobaldo _Herzum_
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
Jun 10, 2022

Hi @Shraddha Sudheendra ,

welcome to the Atlassian community!

As specified here https://jira.atlassian.com/browse/CONFSERVER-61266 :

 

Affected versions of Team Calendar in Confluence Server allow attackers to inject arbitrary HTML or Javascript via a Cross Site Scripting vulnerability in admin global setting parameters.

Affected versions:

  • < 7.11.0

Fixed version:

  • 7.11.0

Hope this helps,

Fabio

Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
Jun 10, 2022

I recommend upgrading to a 7.13.x version as it will contain the fix for https://jira.atlassian.com/browse/CONFSERVER-61266

But more specifically, upgrade to 7.13.7 as this also contains the fix for the more recent Advisory.  Plus this version is part of our Long term support releases, which ensures this minor version will continue to receive critical fixes throughout its supported term.

Like # people like this
1 vote
Alex Koxaras _Relational_
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
Jun 10, 2022

Hi @Shraddha Sudheendra and welcome to the community!

From what I read you had to upgrade the version of Confluence. According to this https://jira.atlassian.com/browse/CONFSERVER-61266?jql=labels%20%3D%20CVE-2020-29444 your version is most likely affected.

You could also try to upgrade the Team Calendar as it is stated here https://confluence.atlassian.com/teamcal/team-calendars-7-0-16-release-notes-1050549224.html

0 votes
Steven Schouppe
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
Jun 10, 2022

Hi @Shraddha Sudheendra ,

Welcome!

As suggested here already, you should be OK if you're on the most recent LTS (= 7.13.7 today) and update Teams Calendar along with it.

LTS 7.13.7 will also introduce a fix for CVE-2022-26134.

Cheers,
Steven

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
VERSION
7.4.11
TAGS
AUG Leaders

Atlassian Community Events