20 ms·
They updated the details of the CVE to state that it affects servers where that setting is disabled, as well. From the source ticket: > Our Securities Team has
by thatsamonad 5y ago
They updated the details of the CVE to state that it affects servers where that setting is disabled, as well. From the source ticket:
> Our Securities Team has since reviewed the wording on the Confluence Security Advisory CVE-2021-26084 - OGNL injection - 2021-08-25 and have removed the ambiguity generated by:
The vulnerable endpoints can be accessed by a non-administrator user or unauthenticated user if ‘Allow people to sign up to create their account’ is enabled. To check whether this is enabled go to.
There are additional endpoints identified that still expose Confluence to the CVE-2021-26084 Confluence Server Webwork OGNL injection and applying the workaround script will assist in temporarily mitigating against all known vulnerable endpoints until the application is upgraded to the fixed version.
The temporary workaround script must be run even if Confluence Administration > User management > User Signup Options > Allow people to sign up to create their account is not enabled.
https://jira.atlassian.com/browse/CONFSERVER-67940 https://jira.atlassian.com/browse/CONFSERVER-67940