Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Is there any patch available to prevent this attack "https://searchsecurity.techtarget.com/news/2525

software_tspl_tallysolutions_com
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
September 3, 2021

Is there any patch available to prevent this attack? Any suggestion or recommended method?

"https://searchsecurity.techtarget.com/news/2525

3 answers

1 accepted

1 vote
Answer accepted
Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
September 3, 2021
Kishan Sharma
Community Champion
September 3, 2021

Yes, there's already a workaround for affected versions listed on this link.

software_tspl_tallysolutions_com
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
September 3, 2021

Thanks for the prompt response.

Like Kishan Sharma likes this
0 votes
Daniel Ebers
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
September 8, 2021

Hi @software_tspl_tallysolutions_com

are you already affected by malicious code running on your server placed there by a hacker?

I am asking because while patching the vulnerable Confluence installation alongside with removing the malicious crypto miner is the correct measure in first place you would need to assess if the server is compromised in a way it needs probably to be restored from backup.

Basically if a machine got hacked it should not be trusted anymore. In case this applies, please do a thorough check of the environment, too. The malware seen in that cases is reported to "jump" to other hosts, too.

Regards,
Daniel

0 votes
David Dellinger September 4, 2021

Hi,

Do we run the mitigation script first, then patch? Or do we only patch? I have my server's network turned off at the moment, and patching wants to do a yum update, so I'm not sure if the patch will work.

Thanks!

David

Kishan Sharma
Community Champion
September 4, 2021

Running the workaround/mitigation script is recommended which will temporarily mitigate the issue until you can upgrade to a version that fixes this permanently. 

David Dellinger September 8, 2021

Great, thanks for the update.

I did just that - restored from backup, ran the mitigation script, turned on networking, then applied the 7.13.0 patch. Everything is working great now and we're not seeing any evidence of infection (on any of our servers).

David

Like Kishan Sharma likes this
Kishan Sharma
Community Champion
September 8, 2021

good to know, David!

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events