Dear customer,
On the 16th of January 2024, Atlassian issued a Security Advisory for Confluence Server & Confluence Data Center. The Cloud versions of the applications as well as other Atlassian products are not affected.
What you need to know
Atlassian has discovered that a template injection vulnerability on out-of-date versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected version.
Customers using an affected version must take immediate action.
Please NOTE: Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.
Affected Versions
Product | Affected Versions |
---|---|
Confluence Data Center and Server |
|
What should I do?
You use Confluence Data Center and Server
Update
If you are on an out-of-date version, you must immediately patch.
Atlassian recommends that you patch each of your affected installations to the latest version available.
The listed Fixed Versions are no longer the most up-to-date and do not protect your instance from other non-critical vulnerabilities as outlined in Atlassian’s January Security Bulletin.
Product | Fixed Versions | Latest Versions |
---|---|---|
Confluence Data Center and Server |
|
|
Confluence Data Center |
|
|
Mitigation
There are no known workarounds. To remediate this vulnerability, update each affected product installation to the latest version.
You use Confluence Cloud
You are not affected by this Security Advisory. No need for action.
You use Confluence on servers operated by bitvoodoo
You are not affected by this Security Advisory. No need for action.
Support
If you still have questions or concerns regarding this advisory, please contact the bitvoodoo support via support.bitvoodoo.ch.