Security advisory for Confluence Server and Confluence Data Center

Kashif Pervaiz September 12, 2019

Hi,

I have a question about the recent advisory.

https://confluence.atlassian.com/doc/confluence-security-advisory-2019-08-28-976161720.html

If the maintenance period has expired, how can we protect ourselves from the vulnerability without renewing the license?

1 answer

0 votes
Daniel Eads
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
September 12, 2019

Hi Kashif,

The advisory does contain mitigation steps if you're unable to upgrade:

Mitigation

If you are unable to upgrade Confluence immediately or are in the process of migrating to Confluence Cloud, then as a temporary workaround you can use the atlassian.confluence.export.word.max.embedded.images  system property to set the maximum number of images to include in Word exports to zero. This will prevent images from being embedded in Word exports.

You'll want to read the full steps for applying this in the Mitigation section of the advisory as the exact steps depend on what operating system you're running on.

 

Depending on your Confluence version, you'll also want to view mitigation steps for two other security advisories released earlier this year:

 

As we continue to invest in security research, it may be worthwhile to evaluate renewing your support maintenance to get access to the latest bugfix releases. We've been lucky so far that security researchers have found easy-to-remediate items, but that's no guarantee that it will always be like this in the future.

Cheers,
Daniel | Atlassian Support

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events