Hi Team,
I just received confluence security advisory warning notification from atlassian. We have confluence server version 6.0.3, this version is not in the list of versions which have effect.
Just want to confirm with you, Does security advisory which is released for confluence server or database today will effect our confluence version 6.0.3?
Thanks!
Regards,
Niveditha
Hi Niveditha -
I believe that 6.0.3 is impacted based on the following in the release announcement:
- From version 2.0.0 before 6.6.13 (the fixed version for 6.6.x)
So, you would need to get up to version 6.6.13 at the minimum.
-Ed
Hi Ed,
Thanks for the quick reply!
I found this list in the provided link, according to this our version doesn't have effect. So please let us know what would be the impact.
Thank you!
Regards,
Niveditha
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Niveditha ,
I can 100% confirm that all versions of 6.0.x are affected. The omission from the advisory is an error on our end, which we will correct shortly.
The impacts are outlined on the advisory itself:
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs, or to create a new space or personal space, or who has 'Admin' permissions for a space, can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center.
You will need to upgrade Confluence to a version listed on the advisory to patch the vulnerability. There is a short-term mitigation step listed in the advisory as well to protect you while you work on upgrading.
Best,
Daniel | Atlassian Support
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.