Australian software developer Atlassian has announced eight vulnerabilities in its enterprise Wiki product, Confluence.
The company recommends that Confluence users upgrade to version 3.4.6, which fixes all the issues, as soon as possible. Users unable to do so are advised they can instead “disable public signup to your wiki until you have applied the necessary patch or upgrade. For even tighter control, you could restrict access to trusted groups.”
The eight vulnerabilities are:
1. Vulnerability in Code macro, affecting Confluence 2.7 -- 3.4.
2. Vulnerability in Attachments macro, affecting Confluence 3.3 -- 3.4.
3. Vulnerability in Bookmarks macro, affecting Confluence 3.1 -- 3.4.3.
4. Vulnerability in Global Reports macro, affecting Confluence 2.7 -- 3.4.3.
5. Vulnerability in Recently Updated macro, affecting Confluence 3.0 - 3.4.3.
6. Vulnerability in Pagetree macro, affecting Confluence 2.7 - 3.4.3
7. Vulnerability in Create Space Button macro, affecting Confluence 2.7 - 3.4.3.
8. Vulnerability in Documentation Link macro, affecting Confluence 2.7 -- 3.4.5
The statement announcing the flaws thanked “Dave B” for alerting the company to the issues, and added that “We fully support the reporting of vulnerabilities and we appreciate it when people work with us to identify and solve the problem.”