Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Is the HOTFIX workaround for CVE-2021-26084 still viable?

James Waithe September 21, 2021

Our team is planning to upgrade the Confluence servers, but in the meantime, has there been any feedback on the effectiveness of the workaround?

1 answer

0 votes
Kishan Sharma
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
September 21, 2021

Hi @James Waithe Welcome to the Atlassian Community!

If you cannot upgrade your confluence instance immediately, applying the workaround script will assist in temporarily mitigating against all known vulnerable endpoints and is highly recommended. You may find some useful comments from other users regarding the workaround script on this issue.If you have questions or concerns regarding the CVE advisory, please raise a support request at https://support.atlassian.com/contact.

James Waithe September 24, 2021

Thank you @Kishan Sharma I am sure the Workaround is holding.  

My question was more about if any researchers or threat actors have tried to find a workaround "around" the workaround since it was first published. 

Kishan Sharma
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
September 24, 2021

Hopefully someone from Atlassian Team check this thread and comment on this. I would also recommend adding a comment on this issue directly so that you might get some answers.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events