We are running Confluence on a VM using Docker image atlassian/confluence-server:7.5.0 - image ID 7e67fc285c1b and we are no longer covered under Atlassian's support. Do I have any path in mitigating the security vulnerability described in CVE-2021-26084 without purchasing new support coverage from Atlassian?
Since I have the Confluence INSTALLATION_DIRECTORY mounted to a volume, I pointed the cve-2021-26084-update.sh script to that directory and ran it. The script successfully ran and I restarted Confluence. Seems kind of awkward and I'll have to remember to run again if I have to rebuild the volume. But at least the patch appears applied.
Hi @Bob Calder thanks for sharing, you have already got it working. Similar case was discussed here with a solution, you can refer to it.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.