Dear customer, On the 16th of January 2024, Atlassian issued a Security Advisory for Confluence Server & Confluence Data Center. The Cloud versions of the applications as well as other Atlassian products are not affected. What you need to knowAtlassian has discovered that a template injection vulnerability on out-of-date versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected version. Customers using an affected version must take immediate action. Please NOTE: Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin. Affected Versions Info |
---|
Product | Affected Versions |
---|
Confluence Data Center and Server | 8.0.x 8.1.x 8.2.x 8.3.x 8.4.x 8.5.0-8.5.3
|
|
What should I do? Localtab Group |
---|
Localtab |
---|
active | true |
---|
title | Confluence Server & Data Center |
---|
tabIcon | bvicon-server |
---|
| You use Confluence Data Center and Server UpdateIf you are on an out-of-date version, you must immediately patch. Atlassian recommends that you patch each of your affected installations to the latest version available. The listed Fixed Versions are no longer the most up-to-date and do not protect your instance from other non-critical vulnerabilities as outlined in Atlassian’s January Security Bulletin. Product | Fixed Versions | Latest Versions |
---|
Confluence Data Center and Server | | | Confluence Data Center | 8.6.0 (Data Center Only) 8.7.1 (Data Center Only)
| |
MitigationThere are no known workarounds. To remediate this vulnerability, update each affected product installation to the latest version.
|
Localtab |
---|
title | Atlassian Confluence Cloud |
---|
tabIcon | bvicon-cloud |
---|
| You use Confluence Cloud Tip |
---|
You are not affected by this Security Advisory. No need for action. |
|
Localtab |
---|
title | bitvoodoo Cloud |
---|
tabIcon | bvicon-cloud |
---|
| You use Confluence on servers operated by bitvoodoo
Tip |
---|
You are not affected by this Security Advisory. No need for action. |
|
|
Support If you still have questions or concerns regarding this advisory, please contact the bitvoodoo support via support.bitvoodoo.ch. |