Hi All,
Back in December when log4j was reported an issue for java applications, Confluence forums reported it was not an issue for their product.
I am however still seeing alerts from our tenable scans that say it is vunerable
Please can you confirm if this is still an issue?
Path : /opt/atlassian/confluence/confluence/WEB-INF/lib/log4j-1.2.17-atlassian-3.jar Installed version : 1.2.17 Path : /opt/backup/plugins-cache/1440495795000gliffy-confluence-plugin-6.7.0.jar Installed version : 1.2.17 Path : /opt/backup/plugins-osgi-cache/felix/felix-cache/bundle218/version0.0/1440495795000gliffy-confluence-plugin-6.7.0_1440495795000.jar-embedded/META-INF/lib/log4j-1.2.17.jar Installed version : 1.2.17 Path : /opt/backup/plugins-osgi-cache/transformed-plugins/1440495795000gliffy-confluence-plugin-6.7.0_1440495795000.jar Installed version : 1.2.17
Severity | State | Port | Assets |
---|---|---|---|
Active | N/A |
Similar post....
I suggest reporting to Atlassian support also of interest reference Atlassian Trust
Ah! Apologies, I thought I raised this as an Atlassian support ticket.
I will close this off.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.