is version 4.1.9 affected? you say 'All versions of Confluence up to and including 4.1.7 are affected by this vulnerability'. but state that the fix for 4.1 is in 4.1.10.
"It has been discovered that 4.1.9 contains an incomplete fix and is still vulnerable to a small subset of the issues above. Namely, a logged in administrator is still able to use the Denial of Service exploit. This is a very small risk in most environments and you may be able to treat 4.1.9 as not affected."
The advisory text is now updated.
Hello Community, Jessica here from the Confluence product marketing team! Today I wanted to get your takes on project planning –– what works, what doesn’t, how do you know if you’re doing it r...
Connect with like-minded Atlassian users at free events near you!Find a group
Connect with like-minded Atlassian users at free events near you!
Unfortunately there are no AUG chapters near you at the moment.Start an AUG
You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs