Is there a work around?
Hi @smarlowWWF,
It seem yes (for specific Confluence versions) - FAQ for CVE-2021-42574.
We recommend upgrading as soon as possible if you are on an affected version, but as a temporary workaround, you can mitigate the issue by deploying a new JAR file that contains the fix.
The temporary workaround can be applied on one node at a time without shutting down the whole Confluence cluster. There are no dependencies between nodes for the workaround JAR file.
The temporary workaround is supported only for Confluence 7.4.9 and later.
For Confluence 7.4.8 and older, please upgrade to a fixed version of Confluence.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.