News: 1629957640

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Atlassian warns of critical Confluence flaw

(2021/08/26)


Atlassian has warned users of its Confluence Server that they need to patch the product to remedy a Critical-rated flaw.

The company's not saying a lot about [1]CVE-2021-26084 , besides describing it as a "Confluence Server Webwork OGNL injection vulnerability … that would allow an authenticated user, and in some instances unauthenticated user, to execute arbitrary code on a Confluence Server or Data Center instance."

The bug scores 9.8 on the ten-point Common Vulnerability Scoring System.

[2]

Atlassian has released fixed versions of the product – namely versions 6.13.23, 7.4.11, 7.11.6, 7.12.5, and 7.13.0 – but the company's [3]advisory suggests upgrading to the latest long-term service release.

[4]

[5]

That means version 7.13, which was released last week – nine days before disclosure of this flaw.

[6]Looks like people now pay for Trello, meaning 'ripper' fourth quarter at Atlassian

[7]There is no escape: Atlassian to send Jira into places only Excel dares to tread

[8]Trello moved 'Facelift' card to Completed on Go Live board

Atlassian's advisory notes that a full upgrade is not possible for all users, so they need to step up to the clean double-point versions mentioned above before contemplating the step to version 7.13.

Cloud-hosted Confluence is not impacted by the bug.

Atlassian's documentation for the bug is not very detailed. It almost certainly refers to the Object-Graph Navigation Language (OGNL), a [9]project that offers an expression language for getting and setting properties of Java objects. Atlassian hasn't mentioned whether the flaw has its roots in open-source code, or its own efforts. The Register cannot find a reference to the flaw beyond the Australian company's advisory and documents.

[10]

The flaw was discovered by Benny Jacob (SnowyOwl) through the Atlassian public bug bounty program. ®

Get our [11]Tech Resources



[1] https://jira.atlassian.com/browse/CONFSERVER-67940

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YSdmZoS4iJ2ZVLZAlfARVAAAAME&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YSdmZoS4iJ2ZVLZAlfARVAAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YSdmZoS4iJ2ZVLZAlfARVAAAAME&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2021/08/25/atlassian_trello_pricing/

[7] https://www.theregister.com/2021/04/28/jira_work_management/

[8] https://www.theregister.com/2021/02/17/trello_update/

[9] https://commons.apache.org/proper/commons-ognl/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YSdmZoS4iJ2ZVLZAlfARVAAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://whitepapers.theregister.com/



Water, taken in moderation cannot hurt anybody.
-- Mark Twain