Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Confluence Security Advisory - 2021-08-25

Marsel Achkelyamov September 7, 2021

https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html?utm_source=alert-email&utm_medium=email&utm_campaign=Confluence%20Server%20and%20Data%20Center-advisory_september-2021_EML-11511&jobid=105178881&subid=1622470293

Hello everyone!
Could you please tell me the difference between Confluence temporary solution (script) and a normal service update?
And let me also ask, how temporary is this solution? After how long will it stop protecting?

1 answer

1 accepted

1 vote
Answer accepted
Alexis Robert
Community Champion
September 7, 2021

Hi @Marsel Achkelyamov , 

 

the script is a workaround because it patches the vulnerability only, and will be lost if you upgrade to another Confluence version that is affected by the Security Advisory.

The script is best if you don't want to change your Confluence version because you might need to test it before, and make sure that all your addons work fine for example. 

 

Let me know if this helps, 

 

--Alexis

Marsel Achkelyamov September 7, 2021

Thank you so much Alexis!

Vedant Kulkarni_Trundl
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
September 7, 2021

@Alexis RobertDoes this vulnerability issue have an impact on Confluence running behind the VPN? Some of the customers have not exposed their Confluence publicly.

Alexis Robert
Community Champion
September 7, 2021

Even if your Confluence is behind a VPN or generally not opened on the internet the vulnerability could still be used by an internal user. That's why it's important to patch even in this case.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events