https://confluence.atlassian.com/doc/confluence-security-adv... https://twitter.com/USCERT_gov/status/1532511428451631108?t=...
https://confluence.atlassian.com/doc/confluence-security-adv... https://twitter.com/USCERT_gov/status/1532511428451631108?t=...
Posting this high here so it can be seen.
https://gist.github.com/noahbailey/0260efa836b4ea67163cbfeef...
The ONLY correct solution here is to bring the servers offline until there is a patched version to upgrade to. Anything else would be a terrible idea.
_sometimes_ there is only one config setting that's affected, or some other often lesser-used feature that can be disabled. But it highly depends on the method used.
location ~\* \$\{. {
deny all;
}
but this only helps if this vulnerability is triggered using the request uri otherwise it's useless RewriteEngine On
RewriteCond %{REQUEST_URI} ^.*\${.*$
RewriteRule ^/(.*) https://google.com [R=302,L]
seems to work ... http-request deny if { path -m sub ${ }
http-request deny if { query -m sub ${ }
http-request deny if { path -m sub $%7B }
http-request deny if { query -m sub $%7B }
http-request deny if { path -m sub %24%7B }
http-request deny if { query -m sub %24%7B }See https://confluence.atlassian.com/doc/confluence-security-adv...
It is strange that they didn't have mitigation steps earlier, but I'm guessing Atlassian announced this immediately since it was already being exploited.