Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Do you have a plan to fix CVE-2021-34429

guowu Hu
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
August 9, 2022

Our confluence's version 7.13.7, And our security team found a issue which name is  CVE-2021-34429, And We want to know: Do you have a plan to fix CVE-2021-34429

2 answers

0 votes
Daniel Ebers
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
August 16, 2022

Hi @guowu Hu

I not able to follow where it comes from the security department assumes CVE-2021-34429 would be affecting your installation - is there more information you could provide to understand that better?

Regards,
Daniel

0 votes
Fabio Racobaldo _Catworkx_
Community Champion
August 9, 2022

Hi @guowu Hu ,

welcome to the Atlassian community!

Confluence 7.13.7 is not impacted by CVE-2021-34429. Based on this article I upgraded a customer instance to 7.13.7 and issue has been fixed.

If you go to the Troubleshooting and support tool (on the admin section) you will se that 7.13.7 security check is ok.

Hope this helps,

Fabio

guowu Hu
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
August 16, 2022

Hi @Fabio Racobaldo _Catworkx_  , Thanks for your reply, But I has some questions. 

1、I check the article what you provide , https://www.cve.org/CVERecord?id=CVE-2022-26134 , It show  CVE-2022-26134, Do you mean you fix CVE-2022-26134 then CVE-2021-34429 will fixed too?

2、You said that confluence 7.13.7 is not impacted by CVE-2021-34429, But our security team scan confluence and got the issue which include CVE-2021-34429, I don't know why. Our confluence was recently upgraded from 7.13.2 to 7.13.7, Is the history file left after the upgrade causing the scan result to be abnormal?

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events