Is Confluence vulnerable to the "Apache Commons Collections Java library insecurely deserializes data" issue?

November 16, 2015

This question is in reference to Atlassian Documentation: Confluence Security Overview and Advisories

There's a severe security issue in the ACC library. I wanted to ask if Confluence is also vulnerable to this issue and if so, if there will be a fix for this soon.

Thanks for your help

1 answer

1 accepted

0 votes
Answer accepted
January 5, 2016

To answer my own question: Yes it is, and the update to Confluence 5.9.3 updates the ACC library and therefore fixes this vulnerability.

Suggest an answer

Log in or Sign up to answer
AUG Leaders

Atlassian Community Events