is version 4.1.9 affected? you say 'All versions of Confluence up to and including 4.1.7 are affected by this vulnerability'. but state that the fix for 4.1 is in 4.1.10.
"It has been discovered that 4.1.9 contains an incomplete fix and is still vulnerable to a small subset of the issues above. Namely, a logged in administrator is still able to use the Denial of Service exploit. This is a very small risk in most environments and you may be able to treat 4.1.9 as not affected."
The advisory text is now updated.
Connect with like-minded Atlassian users at free events near you!Find a group
Connect with like-minded Atlassian users at free events near you!
Unfortunately there are no AUG chapters near you at the moment.Start an AUG