After applying the mitigation script fix, that was provided by Atlassian, to patch our instance of Confluence 7.4.8 we have ran into an issue with serving up articles through our Customer Portal in Jira Service Desk and via the Agent View.
Customers and agents are able to search and find articles but cannot view them. The remotepageview frame displays that our Confluence instance has refused the connection. Using the inspector tool, I can see that remoteviewpage link is returning a 404 response but the article being viewed does exist.
Both of our JSD and Confluence instances use CAS Auth to authenticate users.
Has anyone else run into this issue who uses CAS authentication on their Confluence instance?
Article detailing the vulnerability: https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html
Turns out the remotepageview plugin was somehow disabled in our instance. Works fine now with it enabled back....
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.