Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

CVE-2021-26084 - Mitigation by Turning off "Allow people to sign up to create their account"

David Klebanoff
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
August 25, 2021

With respect to this vulnerability, do we have to run the mitigation script at all if we have "Allow people to sign up to create their account" turned off ?

 

2 answers

1 vote
Malcolm Ninnes
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
August 25, 2021

Atlassian recommends running the workaround/mitigation script even if 'Allow people to sign up to create their own account' is disabled.  There are several endpoints identified that expose Confluence to CVE-2021-26084, so applying the workaround script will temporarily mitigate against the known vulnerable end points until you can upgrade to a version that fixes this permanently.

We've reworded the advisory (Confluence Security Advisory CVE-2021-26084 - OGNL injection - 2021-08-25) to remove any ambiguity.  

0 votes
Kian Stack Mumo Systems
Community Champion
August 25, 2021

My reading of the vulnerability would say no, but I would defer to Atlassian if they say something different. A lot of people have the same question on this ticket. I would add yourself as a watcher to see if Atlassian responds with confirmation.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events