Atlassian released the following advisory last month:
Under the "Acknowledgement" section it says user "Magic Ice Cream Shop" discovered this vulnerability. There is no information on how Magic Ice Cream Shop did it (i.e. how a user with "Add Page" space permission can view files in <install-directory>/confluence/WEB-INF).
Would appreciate if Atlassian can release steps to reproduce this vulnerability so that we can make a determination as to whether an upgrade to fixed version is necessary.
@P , i would not want Atlassian give out the recipe to hack the application while the vulnerability is still a problem.
It is not better to apply the workaround or fix by just understanding that somewhere someone could hack your system?
I think if you are a paying customer (which I am) then Atlassian should inform us at least privately (i.e. does not have to be through this forum).
Knowing how the attack works and trying it on my system is far less work than the upgrading to the nearest fixed version.
If Atlassian prefers, I can launch an actual support ticket. But either way, it is really important for me to know how this vulnerability can be exploited.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Still, as a customer of atlassian, if i got the recipe from atlassian, i could happily exploit the other customers instances. Why would atlassian or any company for that matter do such a thing with their product customers?!
A support ticket or even if i am ready to pay extra money to a company to know how to hack their product, they would (and should) never do that..
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Yes I understand, but this can be taken care of easily by simply signing an agreement identifying myself to Atlassian as a paying customer who has no malicious intent and will not pass this information on to anyone. Kind of like how paying customers have agreed to not pass Atlassian Confluence source code to others.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.