Just a heads up: On March 24, 2025, starting at 4:30pm CDT / 19:30 UTC, the site will be undergoing scheduled maintenance for a few hours. During this time, the site might be unavailable for a short while. Thanks for your patience.
×We were too slow to patch (and don't have maintenance) and our Confluence on-prem is now locked up. I've stopped the thread that was encrypting, but it looks like backups were deleted and attachments encrypted.
Any experiences so far in the community?
I think multiple instances got affected by this vulnerability, some observations are like, home directory is missing, couple of files are locked, random users were created with Admin privileges.
Hi Santosh,
It would be good if you have the backup, would suggest to to create new instance and restore the backup. May be they downloaded not sure about this. Atlassian is trying to mitigate the problem.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
@Mayur Jadhav Do you think there is a home folder download? or it is just remote code execution to prevent use of confluence server?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I have faced the same issue here.. not sure if the whole home folder got downloaded by the hacker...I keep taking weekly backups and found not much data loss for me so far..
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.