Which is very strange, they usually have at least a workaround or URL to block.
See https://confluence.atlassian.com/doc/confluence-security-adv...
It is strange that they didn't have mitigation steps earlier, but I'm guessing Atlassian announced this immediately since it was already being exploited.
location ~\* \$\{. {
deny all;
}
but this only helps if this vulnerability is triggered using the request uri otherwise it's useless RewriteEngine On
RewriteCond %{REQUEST_URI} ^.*\${.*$
RewriteRule ^/(.*) https://google.com [R=302,L]
seems to work ... http-request deny if { path -m sub ${ }
http-request deny if { query -m sub ${ }
http-request deny if { path -m sub $%7B }
http-request deny if { query -m sub $%7B }
http-request deny if { path -m sub %24%7B }
http-request deny if { query -m sub %24%7B }The ONLY correct solution here is to bring the servers offline until there is a patched version to upgrade to. Anything else would be a terrible idea.
_sometimes_ there is only one config setting that's affected, or some other often lesser-used feature that can be disabled. But it highly depends on the method used.