Atlassian warns of critical Confluence flaw
(2021/08/26)
- Reference: 1629957640
- News link: https://www.theregister.co.uk/2021/08/26/atlassian_critical_confluence_flaw/
- Source link:
Atlassian has warned users of its Confluence Server that they need to patch the product to remedy a Critical-rated flaw.
The company's not saying a lot about [1]CVE-2021-26084 , besides describing it as a "Confluence Server Webwork OGNL injection vulnerability … that would allow an authenticated user, and in some instances unauthenticated user, to execute arbitrary code on a Confluence Server or Data Center instance."
The bug scores 9.8 on the ten-point Common Vulnerability Scoring System.
[2]
Atlassian has released fixed versions of the product – namely versions 6.13.23, 7.4.11, 7.11.6, 7.12.5, and 7.13.0 – but the company's [3]advisory suggests upgrading to the latest long-term service release.
[4]
[5]
That means version 7.13, which was released last week – nine days before disclosure of this flaw.
[6]Looks like people now pay for Trello, meaning 'ripper' fourth quarter at Atlassian
[7]There is no escape: Atlassian to send Jira into places only Excel dares to tread
[8]Trello moved 'Facelift' card to Completed on Go Live board
Atlassian's advisory notes that a full upgrade is not possible for all users, so they need to step up to the clean double-point versions mentioned above before contemplating the step to version 7.13.
Cloud-hosted Confluence is not impacted by the bug.
Atlassian's documentation for the bug is not very detailed. It almost certainly refers to the Object-Graph Navigation Language (OGNL), a [9]project that offers an expression language for getting and setting properties of Java objects. Atlassian hasn't mentioned whether the flaw has its roots in open-source code, or its own efforts. The Register cannot find a reference to the flaw beyond the Australian company's advisory and documents.
[10]
The flaw was discovered by Benny Jacob (SnowyOwl) through the Atlassian public bug bounty program. ®
Get our [11]Tech Resources
[1] https://jira.atlassian.com/browse/CONFSERVER-67940
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YSdmZoS4iJ2ZVLZAlfARVAAAAME&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YSdmZoS4iJ2ZVLZAlfARVAAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YSdmZoS4iJ2ZVLZAlfARVAAAAME&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/08/25/atlassian_trello_pricing/
[7] https://www.theregister.com/2021/04/28/jira_work_management/
[8] https://www.theregister.com/2021/02/17/trello_update/
[9] https://commons.apache.org/proper/commons-ognl/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YSdmZoS4iJ2ZVLZAlfARVAAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://whitepapers.theregister.com/
The company's not saying a lot about [1]CVE-2021-26084 , besides describing it as a "Confluence Server Webwork OGNL injection vulnerability … that would allow an authenticated user, and in some instances unauthenticated user, to execute arbitrary code on a Confluence Server or Data Center instance."
The bug scores 9.8 on the ten-point Common Vulnerability Scoring System.
[2]
Atlassian has released fixed versions of the product – namely versions 6.13.23, 7.4.11, 7.11.6, 7.12.5, and 7.13.0 – but the company's [3]advisory suggests upgrading to the latest long-term service release.
[4]
[5]
That means version 7.13, which was released last week – nine days before disclosure of this flaw.
[6]Looks like people now pay for Trello, meaning 'ripper' fourth quarter at Atlassian
[7]There is no escape: Atlassian to send Jira into places only Excel dares to tread
[8]Trello moved 'Facelift' card to Completed on Go Live board
Atlassian's advisory notes that a full upgrade is not possible for all users, so they need to step up to the clean double-point versions mentioned above before contemplating the step to version 7.13.
Cloud-hosted Confluence is not impacted by the bug.
Atlassian's documentation for the bug is not very detailed. It almost certainly refers to the Object-Graph Navigation Language (OGNL), a [9]project that offers an expression language for getting and setting properties of Java objects. Atlassian hasn't mentioned whether the flaw has its roots in open-source code, or its own efforts. The Register cannot find a reference to the flaw beyond the Australian company's advisory and documents.
[10]
The flaw was discovered by Benny Jacob (SnowyOwl) through the Atlassian public bug bounty program. ®
Get our [11]Tech Resources
[1] https://jira.atlassian.com/browse/CONFSERVER-67940
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YSdmZoS4iJ2ZVLZAlfARVAAAAME&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YSdmZoS4iJ2ZVLZAlfARVAAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YSdmZoS4iJ2ZVLZAlfARVAAAAME&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/08/25/atlassian_trello_pricing/
[7] https://www.theregister.com/2021/04/28/jira_work_management/
[8] https://www.theregister.com/2021/02/17/trello_update/
[9] https://commons.apache.org/proper/commons-ognl/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YSdmZoS4iJ2ZVLZAlfARVAAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://whitepapers.theregister.com/