Hello.
I have seen this notice and have a question.
Confluence Security Advisory - 2021-08-25
Confluence Server and Data Center - CVE-2021-26084 - Confluence Server Webwork OGNL injection
https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html
I am using Atlassian Confluence 3.5.2, the Enterprise Wiki.
Will this notice be included in the Affected versions as well as version 3.5.2?
Or is version 3.5.2 excluded from Affected versions?
I wonder if I should patch version 3.5.2 or not.
Thank you in advance.
Best Regards,
Sueyon KO
The notice doesn't apply to 3.5.2 only because it's well past its End of Life (EOL) date.
You may want to look at upgrading Confluence. Be warned, though, you'll probably have to do some intermediate upgrades to get to the most current version (7.13)
That's true, its very old version. I would suggest raising support ticket with Atlassian for further recommendations.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thanks for your comment. I would consider to upgrade with the most current version as soon as possible. Have a great day!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.