Dear Confluence Team,
We have just revealed a security issue on our Confluence server - someone was able to place the below command in the code:
Could you please advise what is the possible way this has been introduced?
The Confluence Server version we run is 7.7.2.
I would be grateful for a prompt response.
Kind regards,
Alicja Mostowik
I can see your confluence version is affected by CVE-2021-26084 - Confluence Server Webwork OGNL injection vulnerability. Please find the mitigation steps mentioned in the link.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.