Is Apache Commons Text used in Confluence server 7.13.7? If so, how can we remediate? Thank you!
Hi @Tony Simon ,
Welcome to Atlassian community.
Confluence 7.13.7 uses commons-text-1.8.jar. At this stage there’s no indication whether arbitrary code execution is possible and security team at Atlassian is already investigating this. So please await for an official announcement from Atlassian .
Thanks,
Srinath T
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I opened a case and received the message that there is nothing found by Atlassian that confluence is vulnerable.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Why not here so anybody can learn from it?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Is it really needed that every customer has to create a support ticket for an official Bug? Wouldn't it be better, when Atlassian post a message for ALL?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.