Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in
Celebration

Earn badges and make progress

You're on your way to the next level! Join the Kudos program to earn points and save your progress.

Deleted user Avatar
Deleted user

Level 1: Seed

25 / 150 points

Next: Root

Avatar

1 badge earned

Collect

Participate in fun challenges

Challenges come and go, but your rewards stay with you. Do more to earn more!

Challenges
Coins

Gift kudos to your peers

What goes around comes around! Share the love by gifting kudos to your peers.

Recognition
Ribbon

Rise up in the ranks

Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!

Leaderboard

Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,456,571
Community Members
 
Community Events
176
Community Groups

Vulnarability reported for Confluence 7.19.0 LTS

We are using Confluence 7.19.0 LTS and the pentest reported a vulnerability in our Confluence. If we upgrade to 7.20.2. will the Jquery be updated to a 3.X version?

 

The library jquery version 2.2.4 has known security issues.
For more information, visit those websites:
- https://github.com/jquery/jquery/issues/2432
- http://blog.jquery.com/2016/01/08/jquery-2-2-and-1-12-released/
- https://nvd.nist.gov/vuln/detail/CVE-2015-9251
- http://research.insecurelabs.org/jquery/test/
Affected versions
The vulnerability is affecting all versions prior 3.0.0-beta1 (between 1.12.3 and 3.0.0-beta1)

2 answers

1 accepted

2 votes
Answer accepted
Andy Heinzer Atlassian Team Dec 02, 2022

Hi @Cor Zijlstra 

I understand from the description that you are trying to understand if Confluence server running on 7.19.0 version is using a vulnerable version of jQuery(2.2.4), related to CVE-2015-9251

I have checked internally with our security team about Confluence being affected by the CVE-2015-9251 vulnerability, and they verified that this exploit is not affecting Confluence 7.0.1 or newer.  

This is not version 3 of jQuery, but Atlassian maintains its own fork of jQuery, and that forked version has been patched. 

Atlassian forked jQuery 2.2.4

  • Confluence is being shipped with a custom version of the jquery library (atlassian-plugins-jquery 2.2.4.10), which contains a fix for these vulnerabilities, so there should be no issues.
  • For example, if you analyze the jquery-min.js that is bundled in the Confluence 7.19.0, you will see modifications in the code that say Modified by Atlassian, which have been put in place to patch any particular CVEs against this jQuery library that have been reported.

I hope this helps.

Regards,

Andy

Hi Andy,

 

Sorry for not requesting this follow-up question in the previous request.
Does this also apply to moment.js?

 

The library moment.js version 2.29.3 has known security issues.
For more information, visit those websites:
- https://security.snyk.io/vuln/SNYK-JS-MOMENT-2944238
- https://github.com/moment/moment/security/advisories/GHSA-wc69-rhjr-hc9g
Affected versions
The vulnerability is affecting all versions prior 2.29.4 (between 2.18.0 and 2.29.4)

0 votes
Rilwan Ahmed Community Leader Nov 29, 2022

Hi @Cor Zijlstra ,

If you have found a vulnerability, please report it in https://www.atlassian.com/trust/security/report-a-vulnerability 

If you are looking for support, then please raise a ticket in https://support.atlassian.com/contact/#/

If I follow both suggested URL's I finally end up here in the community again,.

Probably because of the starter license?

Thx!

@Rilwan Ahmed Is it the starter license?

Suggest an answer

Log in or Sign up to answer
TAGS

Atlassian Community Events