Atlassian disabled them for a "critical vulnerability"

Anyone care to guess what they may have done so wrong? Do we need to find out so that we do not make the same mistake?

https://wiki.apps.thelab.ms/en/kb-migration

https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html

We have already covered it?

https://talk.dallasmakerspace.org/t/resolved-confluence-source-is-down-for-maintenance-for-a-few-hours-6-pm-2023-10-29/103747/3

The instance of Confluence DMS has running at this time is not impacted by the vulnerability you are referencing. We also have daily backups.

It’s hard to say what the situation at TheLab is with their instance being down though it’s most likely related to that CVE.

It is hard to believe they would be disabled simply for not applying the patch quickly enough. It had to be something more or else.

TheLab ditched Confluence.

Any chance we will do the same?

1 Like

This is bad. Very very bad…

1 Like

Did you get your email about this? Sounds like we made a shift that should have fixed the problem.

1 Like

Yes, that is what made me look at this again.

We have no firm plans to move at this time but that can change.

The IT volunteers tend to discuss “what if’s” like this all the time. The challenge is finding something that better meets our needs, at a price point we can afford, and we can get our 100% volunteer team to execute on in a reasonable amount of time.

We are not impacted by this. We reinstalled a patched version of Confluence on a new VM.

2 Likes