I need to fix the vulnerability, CVE-2020-29444 in Confluence server and Data center. I am not able to find any articles related to this. I need to know the information on the affected versions, fixed version etc.
Hi @Shraddha Sudheendra ,
welcome to the Atlassian community!
As specified here https://jira.atlassian.com/browse/CONFSERVER-61266 :
Affected versions of Team Calendar in Confluence Server allow attackers to inject arbitrary HTML or Javascript via a Cross Site Scripting vulnerability in admin global setting parameters.
Hope this helps,
Fabio
I recommend upgrading to a 7.13.x version as it will contain the fix for https://jira.atlassian.com/browse/CONFSERVER-61266
But more specifically, upgrade to 7.13.7 as this also contains the fix for the more recent Advisory. Plus this version is part of our Long term support releases, which ensures this minor version will continue to receive critical fixes throughout its supported term.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Shraddha Sudheendra and welcome to the community!
From what I read you had to upgrade the version of Confluence. According to this https://jira.atlassian.com/browse/CONFSERVER-61266?jql=labels%20%3D%20CVE-2020-29444 your version is most likely affected.
You could also try to upgrade the Team Calendar as it is stated here https://confluence.atlassian.com/teamcal/team-calendars-7-0-16-release-notes-1050549224.html
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Shraddha Sudheendra ,
Welcome!
As suggested here already, you should be OK if you're on the most recent LTS (= 7.13.7 today) and update Teams Calendar along with it.
LTS 7.13.7 will also introduce a fix for CVE-2022-26134.
Cheers,
Steven
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.