Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Suspicious Alert

michael avanzato June 8, 2022

Hi,

We had an email alert telling us about a Jira Confluence Server Vulnerability, and we needed to check in ASAP whether this is affecting us or not, and if we need to patch. 

We are on Jira version 8.21.0, which the email alert says would be affected. If anyone could please assist us with how we should go about resolving or patching this, it would be appreciated. I've attached a screenshot of the alert message below, thank you!

 

 

 atlassian vulnerability.png

 

 

2 answers

2 accepted

0 votes
Answer accepted
Fabio Racobaldo _Herzum_
Community Champion
June 8, 2022

Hi @michael avanzato ,

CVE-2022-26134 is a real security alert. In order to fix it, my suggestion is to follow the Atlassian offcial article https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html

Hope this helps,

Fabio

0 votes
Answer accepted
Srinatha T
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
June 8, 2022

Hi @michael avanzato ,

Welcome to Atlassian community. 

Yes the email is suspicious. Below is the original advisory released by Atlassian. This is detected in Confluence and not in Jira. 

Have a good day!

Thanks,

Srinath T 

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events