Atlassian’s Confluence has hit a major remote code execution bug

Fixes include upgrading to the latest version

The vulnerability affects versions 5.2, 7.19.0, 7.20.0, 8.0.0, 8.1.0, 8.2.0, 8.3.0, 8.4.0, 8.5.0, 8.6.0, 8.8.0, 8.7.1, 8.9.0 for Confluence Data Center and Atlassian Server. Bug fixes are included in versions 8.9.1, 8.5.9, and 7.19.22, patching all affected versions.

“Atlassian recommends that Confluence Server customers upgrade to the latest version,” Atlassian said in an advisory. “If you can’t do that, upgrade your instance to a single version of the default based types.”

Additionally, SonicWall has provided two Intrusion Prevention Signatures (IPS) for customers to prepare against exploits.


Source link