Hi,
I have a question about the recent advisory.
https://confluence.atlassian.com/doc/confluence-security-advisory-2019-08-28-976161720.html
If the maintenance period has expired, how can we protect ourselves from the vulnerability without renewing the license?
Hi Kashif,
The advisory does contain mitigation steps if you're unable to upgrade:
Mitigation
If you are unable to upgrade Confluence immediately or are in the process of migrating to Confluence Cloud, then as a temporary workaround you can use the
atlassian.confluence.export.word.max.embedded.images
system property to set the maximum number of images to include in Word exports to zero. This will prevent images from being embedded in Word exports.
You'll want to read the full steps for applying this in the Mitigation section of the advisory as the exact steps depend on what operating system you're running on.
Depending on your Confluence version, you'll also want to view mitigation steps for two other security advisories released earlier this year:
As we continue to invest in security research, it may be worthwhile to evaluate renewing your support maintenance to get access to the latest bugfix releases. We've been lucky so far that security researchers have found easy-to-remediate items, but that's no guarantee that it will always be like this in the future.
Cheers,
Daniel | Atlassian Support
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.