Our team is planning to upgrade the Confluence servers, but in the meantime, has there been any feedback on the effectiveness of the workaround?
Hi @James Waithe Welcome to the Atlassian Community!
If you cannot upgrade your confluence instance immediately, applying the workaround script will assist in temporarily mitigating against all known vulnerable endpoints and is highly recommended. You may find some useful comments from other users regarding the workaround script on this issue.. If you have questions or concerns regarding the CVE advisory, please raise a support request at https://support.atlassian.com/contact.
Thank you @Kishan Sharma I am sure the Workaround is holding.
My question was more about if any researchers or threat actors have tried to find a workaround "around" the workaround since it was first published.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hopefully someone from Atlassian Team check this thread and comment on this. I would also recommend adding a comment on this issue directly so that you might get some answers.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.