Hello,
from 2 days, the user "confluence" cause a 100% CPU load with process "-bash"
How i can stop this problem?
Thank you
Hi Denis,
Given the timeframe you mentioned, what you've described is an active exploit that attacks the CVE-2019-3396 Widget Connector vulnerability from March 20th (see Confluence Security Advisory - 2019-03-20).
The first step in fixing this is upgrading to a Confluence version that is not affected by the vulnerability. The latest releases are:
Secondly, the LSD malware cleanup tool will be useful for removing the Kerberods malware. I would recommend executing cleanup after upgrading Confluence to a patched version so there's no possibility of re-infection while you work on the upgrade.
Please let me know if you have more questions!
Daniel | Atlassian Support
Hi @Denis ,
Perhaps you should consider reviewing if any of Confluence internal process is causing this increase on CPU load by Generating a thread dump. There is a script you could use to generate a set of thread dumps along with CPU usage, so you could review which thread is consuming the most of CPU.
Open up the CPU files created, get the highest CPU usages and convert them into HEX https://www.binaryhexconverter.com/decimal-to-hex-converter so you can review its representation in THREADs.
The script creates 1 CPU for 1 THREAD, so you should be comparing the timestamps in the files generated. In this way, when converting PID to HEX, you will be comparing information from a THREAD that relates to CPU taken at the same moment.
In case you are unfamiliar with this troubleshooting process, perhaps you should consider getting in touch with Atlassian Support, so they can provide you with assistance on this issue by gathering more information about your system and instance through Confluence Support Zip and others.
Hope the above helps.
Kind regards,
Rafael
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.