Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

My server rebooted and it went back to installing from scratch

Timothy Ste. Marie November 19, 2023

My server rebooted and it is now prompting me to start from scratch?  Where is my data for my site?  I have backups but how do I get this back up and running?

2 answers

0 votes
BHUSHAN PATIL
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
November 24, 2023

Hi @Timothy Ste. Marie ,

I understand that your confluence server was compromised by CVE-2023-22518, resulting in an unfortunate loss of 18 years' worth of database data.
Experiencing an attack involving data clearing due to CVE-2023-22518 can indeed be immensely challenging. However, there might still be some possibilities for data recovery:

Questions Regarding Your Confluence Server:

  1. Was your Confluence server hosted on AWS or any third-party cloud environment?
    If yes, were snapshots backups enabled? Restoration from previous snapshots might facilitate data recovery.
  2. Do you possess previous Confluence XML backups? Recovery through restoring XML backups on a new Confluence server might help retrieve data.
  3. Are there any database backups available? If yes, restoring the database backup on a new DB server of the same version and re-pointing it to the Confluence application might assist in data recovery.

Remember, data recovery without backups can be exceptionally challenging. Establishing robust backup and disaster recovery strategies is critical to mitigate the impact of such incidents in the future.

Best Regards,
Bhushan

0 votes
Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
November 20, 2023

Welcome to the Atlassian Community!

It depends on what your admins did to the server to make it do this.

Confluence goes into setup mode when its config file does not exist, or is invalid.  Or, if there is a valid config file, but it detects an empty database, it will skip the steps that create the config file and start from the "create core data" step.

"start from scratch" implies an unusable config file.  You can do this by deleting or damaging it, manually, by disk failure (physical data loss, or running out of space), changing the permissions on it.  You can also remove the Confluence users access to it by changing their operating environment variables, although this is unlikely.

First thing to do is check what happened to <confluence home>/confluence.cfg.xml (file name from memory, but it's close, and obvious) - is it there, is it validly formatted, are the permissions right, is the content correct? (the important content is the database connection, the others are mostly just tweaks)

Timothy Ste. Marie November 21, 2023

I found that the server was compromised by the CVE.  Luckily, Atlassian did --NOT-- autopatch my box or contact me with this 10/10 vulnerability so I lost 18 years worth of a database.  Needless to say, no Atlassian or Confluence EVER in my environment.  Moving on to programmers who know how NOT to get hacked.

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
TAGS
AUG Leaders

Atlassian Community Events