Atlassian has announced a critical severity security vulnerability CVE-2021-26084 on certain versions of the Server and Data Center platform for Confluence. Oxalis performed additional analysis on this vulnerability announcement and is confident that our current customers are protected by our security practices. This security vulnerability only affects Atlassian’s Confluence Data Center and Server products. Atlassian Confluence Cloud products are not affected, and users are not impacted by this vulnerability.
Specifically, the CVE (Common Vulnerabilities and Exposures) ID for this vulnerability is: CVE-2021-26084 (Confluence Server Webwork OGNL injection). To stay on top of the issue, track it here. Beyond its extremely high 9.8 severity level, the fact that it doesn’t require a user to be authenticated puts any publicly facing Confluence instance at risk. High profile teams are reporting successful attacks, including the CI/CD tool Jenkins.
We believe it’s critical you mitigate these issues immediately either on your own or through Oxalis’s assistance. US Cybercom has sent out notice to IT teams alerting to this issue, there is reason to believe CVE-2021-26084 will continue and rapidly increase.
This vulnerability specifically affects the following versions of Confluence Server and Data Center:
Affected versions:
What to do if you believe you’re at risk
Upgrade to the latest release
The current releases of Atlassian’s Confluence Server and Confluence Datacenter products have added security patches to address this issue – as long as you have a recent release, you are protected. Staying up to date should be the baseline for security practices.
Check Your Current Version of Confluence
Pick the Version of Confluence to Upgrade and Download
These version apply to both Server and Data Center versions of Confluence:
Versions can be downloaded from the following pages depending on if you are using server or Data Center:
Make a Plan to Stay Up To Date
At Oxalis, we hold regular maintenance windows for all deployments and applications. We continuously monitor, review, and upgrade to new releases for applications like Jira to ensure our client’s systems are up to date.
Patch Your Current Confluence Installation
If for some reason you are unable to upgrade immediately, Atlassian has released a mitigation tool that can be run to remove the vulnerability without upgrading. Full details on downloading and applying the mitigation are available on Atlassian’s page here.
How to avoid future risks
Migrate to Atlassian Cloud
At the beginning of 2021, Atlassian announced their journey to cloud, showing their dedication to the Cloud products and services. Even though they will be decommissioning their Server offering, their Data Center platform will continue to be supported. There are many considerations to take into account before deciding to migrate to Atlassian Cloud, but it is certainly worth considering, as it is clear that Atlassian is focusing their efforts towards the Cloud.
Stay Up To Date
Staying on the most recent version continues to be the best strategy. With stability, it can be easy to end up just staying with what works and getting out of date.
Build Security at Depth
While implementing zero trust architectures can be challenging, choosing architectural patterns that allows for isolation and segmentation of infrastructure components provide both reduced blast radius and limits exploitation.
We’re here to help
If you need help understanding if you’re at risk CVE-2021-26084, hardening your existing infrastructure, are looking for ongoing maintenance help or want to move to a more compliant infrastructure, our award winning team is here to help. As a group of technology consultants and product leaders that operate in various high-compliant industries, Oxalis has a strong focus on security. We don’t just care when vulnerabilities occur, it’s a key piece of how we operate as a firm.
Recommended blog posts
- Confluence Buyer’s Guide: Pricing, Advantages and more
- Effective Enterprise Knowledge Management and Data Quality with Confluence
- Knowledge Management at Enterprise Scale with Confluence Cloud – Webinar [ON-DEMAND]
Contact us
Have some questions about CVE-2021-26084? Oxalis can help you.