Hi,
We have Confluence 6.9.1 installed in our server, it's been running fine from last few years.
Suddenly we started observing system hangs and loads keep going high.
issue is caused by this solrd.
is this called by lucene for indexing ? its starting from /tmp directory. how can we stop it, it keeps coming again and again.
Thanks,
Sunil Saini
updated to the latest version. thanks, helped
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
It's nothing to do with Confluence. Confluence doesn't use solr natively.
Someone has set solr up to run as the confluence user.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
same problem. is it a confluence vulnerability? version 7.2.0
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Please check why 'solr' is hiding in a directory (/tmp/.solr) - the dot means directory is hidden when listing, for example using 'ls' without further parameters.
Or in other words: please make sure if there is no malicious activity on the server - while this is Atlassian community and we're mainly dealing with Atlassian products I just wanted to mention from your picture the system looks not healty. Just make sure it is not hacked.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Dear all,
I also suffered from this solrd process created / runned by confluence1 user. Is it a bug or a hack ? How can I disable this process please?
Many thanks
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
It is a monero mining malware installed through your confluence instance. Check your crontab of the confluence user...
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Very helpful. Do you have any idea how this could happen? Is there a vulnerability in confluence?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Yes (my earlier post was made before I was aware of it). See https://community.atlassian.com/t5/Confluence-articles/Security-Advisory-for-Confluence-Server-and-Data-Center-August/ba-p/1787026
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.