Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-59549

Apache Log4j - Arbitrary Code Execution in confserver/confluence (master)

      Issue Summary

      Arbitrary Code Execution in confserver/confluence (master)

      Steps to Reproduce

      • Vulnerability: Arbitrary Code Execution
      • Severity: High
      • Project: confserver/confluence
      • Branch: master
      • Scan Date: Unknown
        Vulnerability ID: CVE-2019-17571

      log4j-core is vulnerable to arbitrary code execution. Deserialization of untrusted data in `TcpSocketServer` and `UdpSocketServer` when listening for log data allows an attacker to execute arbitrary code via a malicious deserialization gadget.

      View more details

      Expected Results

      N/A

      Actual Results

      N/A

      Workaround

      N/A

            [CONFSERVER-59549] Apache Log4j - Arbitrary Code Execution in confserver/confluence (master)

            7d00cd4efe44 No you wouldn't have this issue in 7.13.2, the issue was fixed in all version above Confluence 7.6.0

            Denise Unterwurzacher [Atlassian] (Inactive) added a comment - 7d00cd4efe44 No you wouldn't have this issue in 7.13.2 , the issue was fixed in all version above Confluence 7.6.0

            Would we have this issue with Confluence 7.13.2

            lance_lyons added a comment - Would we have this issue with Confluence 7.13.2

            If you're running the Confluence 7.4 Enterprise release, a fix for this issue is now available in Confluence 7.4.1, which you can find in the Download Archives.

            Ellen Oates added a comment - If you're running the Confluence 7.4 Enterprise release, a fix for this issue is now available in Confluence 7.4.1, which you can find in the Download Archives .

            A fix for this issue is available to Server and Data Center customers in Confluence 7.5.1
            Upgrade now or check out the Release Notes to see what other issues are resolved.
             

            Ellen Oates added a comment - A fix for this issue is available to Server and Data Center customers in Confluence 7.5.1 Upgrade now or check out the Release Notes  to see what other issues are resolved.  

              hrehioui Hasnae (Inactive)
              akhudavets Andrei Khudavets
              Affected customers:
              1 This affects my team
              Watchers:
              15 Start watching this issue

                Created:
                Updated:
                Resolved: