Atlassian Update
3001Warning Date
Severity Level
Warning Number
Target Sector
19 December, 2019
● Medium
2019-741
All
Description:
Atlassian has released security update to address a vulnerability in following versions of Confluence Server and Confluence Data Center:
- from 7.2.0-beta1 before 7.2.0
- from 6.14.0 before 6.15.10
- from 7.1.0 before 7.1.2
- from 7.0.1 before 7.0.5
- from 6.11.0 before 6.13.10
Threats:
Attacker could exploit this vulnerability by conduction man in the middle (MITM) attack between Confluence Server (or Confluence Data Center) and the atlassian-domain-for-localhost-connections-only.com.
Best practice and Recommendations:
The CERT team encourages users to review Atlassian security advisory and apply the necessary updates:
https://confluence.atlassian.com/doc/confluence-security-advisory-2019-12-18-982324349.html