is 4.1.9 vulnerable?

http://confluence.atlassian.com/display/DOC/Confluence+Security+Advisory+2012-05-17

is version 4.1.9 affected? you say 'All versions of Confluence up to and including 4.1.7 are affected by this vulnerability'. but state that the fix for 4.1 is in 4.1.10.

thanks,

1 answer

1 accepted

0 votes
Accepted answer

"It has been discovered that 4.1.9 contains an incomplete fix and is still vulnerable to a small subset of the issues above. Namely, a logged in administrator is still able to use the Denial of Service exploit. This is a very small risk in most environments and you may be able to treat 4.1.9 as not affected."

The advisory text is now updated.

Suggest an answer

Log in or Sign up to answer
Community showcase
Published Dec 18, 2018 in Confluence Cloud

Happy holidays from our team to yours!

Hi Community!  2018 was filled with changes for our team, both big and small, and we've taken a lot of time to both celebrate our wins and recognize areas of improvement. One thing that we're a...

477 views 3 18
Read article

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you