https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html?utm_source=alert-email&utm_medium=email&utm_campaign=Confluence%20Server%20and%20Data%20Center-advisory_september-2021_EML-11511&jobid=105178881&subid=1622470293
Hello everyone!
Could you please tell me the difference between Confluence temporary solution (script) and a normal service update?
And let me also ask, how temporary is this solution? After how long will it stop protecting?
Hi @Marsel Achkelyamov ,
the script is a workaround because it patches the vulnerability only, and will be lost if you upgrade to another Confluence version that is affected by the Security Advisory.
The script is best if you don't want to change your Confluence version because you might need to test it before, and make sure that all your addons work fine for example.
Let me know if this helps,
--Alexis
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
@Alexis RobertDoes this vulnerability issue have an impact on Confluence running behind the VPN? Some of the customers have not exposed their Confluence publicly.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Even if your Confluence is behind a VPN or generally not opened on the internet the vulnerability could still be used by an internal user. That's why it's important to patch even in this case.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.