Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Are you responsible for any Confluence Server or Data Center instances? (CVE-2022-26134)

Hello Enterprise community!

Are you responsible for any Confluence Server or Data Center instances?

If yes, update your Confluence instance to a patched version, or perform any of the remediation steps in Atlassian's recent Security Advisory, Confluence Security Advisory 2022-06-02. There's a summary of the exploit, and Atlassian has been updating the advisory for the last few days.

  • ✉️ Pro-Tip: If you did not get an email for this advisory and want to receive such emails in the future, go to https://my.atlassian.com/email and subscribe to Alerts emails.

This issue is serious enough to bear repeating, and I know there are a large number of admins in this Enterprise group.

This zero-day attack is actively being exploited across the internet. Ars Technica also posted an article about it.

5 comments

Comment

Log in or Sign up to comment
Dave Liao
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
June 4, 2022

Hopefully you're not responsible for any Confluence on-prem instances, or you've already performed the necessary updates / mitigation steps.

In that case, are you diving into Pokemon Go's 2022 Fest? 😅

Ollie Guan
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
June 4, 2022

Fixed! tks @Dave Liao 

Taranjeet Singh
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
June 9, 2022

Thank you for sharing this in the group, @Dave Liao !

I was performing a Jira Server to Cloud migration when the linked Confluence Server instance was hit by this security vulnerability and attack. Fortunately, bringing down the Confluence Host server (which also was running Crowd Server) did not have any impact on my migration, though I was not able to login to Jira Server for 5 minutes when Confluence host was being bounced.

Kristján Geir Mathiesen
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
July 4, 2022

I meant to thank you for this notice @Dave Liao 

Craig Nodwell
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
August 14, 2022

Thanks for this @Dave Liao 

TAGS
AUG Leaders

Atlassian Community Events