Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

CVE-2022-26134 on confuence version 6.15

Sujit Dash
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
June 6, 2022

What is the impact and how to resolve the 

CVE-2022-26134 - Critical severity unauthenticated remote code execution vulnerability on Confluence version 6.15.2

3 answers

0 votes
Chihara
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
June 12, 2022

Atlassian updated that security advisary on 10/Jun as 

For Confluence 6.0.0 - Confluence 7.14.2

If you run Confluence in a cluster, you will need to repeat this process on each node. You don't need to shut down the whole cluster to apply this mitigation.

....

0 votes
IT Sec
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
June 9, 2022

Hello, @Fabio Racobaldo _Herzum_ 

+1, I also have version 6.15.*
How to fix CVE-2022-26134?
Can you test the fix (For Confluence 7.0.0 - Confluence 7.14.2) for version 6.15.* please?

Thank you.

0 votes
Fabio Racobaldo _Herzum_
Community Champion
June 6, 2022

Hi @Sujit Dash ,

as explained here https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html you should upgrade your instance to one of the version with a fix (7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4 and 7.18.1).

If you can't, the workaround suggested (For Confluence 7.0.0 - Confluence 7.14.2) has not been fully tested for unsupported versions like 6.15.2

Hope this helps,

Fabio

Sujit Dash
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
June 6, 2022

Is there any plan to test it on unsupported versions like 6.15.2?

Like IT Sec likes this

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events