Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Need clarification on security advisories

vishal bhaskar
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
July 4, 2022

Need assistance with the three queries below:

1> For https://jira.atlassian.com/browse/CONFSERVER-74276

There are no fix versions in 7.15.x or 7.14.x. Should we consider them as vulnerable? Also the affected versions only mention 7.13.1, do we consider that version before 7.13.x like 7.4.x or 7.5.x are not vulnerable? We need clear understanding on which version ranges of Confluence are affected and which ones are not.

2> For https://jira.atlassian.com/browse/CONFSERVER-61266

Should we consider all versions before 7.11.0 as affected as mentioned in the description? For example, 7.10.x , 7.9.x ?

3> For https://confluence.atlassian.com/security/multiple-products-security-advisory-hazelcast-vulnerable-to-remote-code-execution-cve-2016-10750-1116292387.html?utm_source=alert-email&utm_medium=email&utm_campaign=bitbucket-data-center-confluence-data-center-security-advisory-march_EML-12770&jobid=105489999&subid=1544944158

Are Confluence Data center versions 7.5.x to 7.12.x affected?

1 answer

1 accepted

1 vote
Answer accepted
Brant Schroeder
Community Champion
October 26, 2022

@vishal bhaskar 

1.  Yes, you should upgrade.  As the link states and version of Confluence 7.13.1 or below

2. Yes anything below 7.11.0

3. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events