Confluence doesn't have "stable" versions, it has versions that are released because they work.
On top of that, the problem here is "This applies to applications that allow untrusted users to upload/modify velocity templates"
Confluence doesn't do that. It's code change (requiring root access to your Confluence server), or being sneaky in user macros (server only, and Confluence admins only).
As you have to trust your admins, with any software, this is not a problem. Untrusted users can't make any form of attack.
Hey @zhangyifei
A good check to see if a product is impacted by a CVE is to search JAC - eg: https://jira.atlassian.com/issues/?jql=text%20~%20%22CVE-2020-13936%22
It's no guarantee, but it is an indicator
CCM
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thanks @Nic Brough -Adaptavist-
Hi @zhangyifei
Upgrade the confluence version to latest stable release, if they do have CVE you mentioned that should be solved,
And FYI if any CVE are found for any Atlassian applications, team will notify customers to upgrade the server
Here's the release notes of latest stable version of confluence
https://confluence.atlassian.com/conf713/confluence-release-notes-1077914914.html
Thanks,
Pramodh
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.