is 4.1.9 vulnerable?

Stephen S. Willey May 17, 2012

http://confluence.atlassian.com/display/DOC/Confluence+Security+Advisory+2012-05-17

is version 4.1.9 affected? you say 'All versions of Confluence up to and including 4.1.7 are affected by this vulnerability'. but state that the fix for 4.1 is in 4.1.10.

thanks,

1 answer

1 accepted

0 votes
Answer accepted
Przemek Bruski
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
May 18, 2012

"It has been discovered that 4.1.9 contains an incomplete fix and is still vulnerable to a small subset of the issues above. Namely, a logged in administrator is still able to use the Denial of Service exploit. This is a very small risk in most environments and you may be able to treat 4.1.9 as not affected."

The advisory text is now updated.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events