Child pages
  • Atlassian Confluence Security Advisory 20 Mar 2019 - Immediate Mitigation
Skip to end of metadata
Go to start of metadata

As a result of the recently published critical security advisory from Atlassian, which we consider to be very critical, we recommend that you disable the following apps as an immediate countermeasure:

  • WebDAV plugin
  • Widget Connector

Disabling these apps immediately protects you against these vulnerabilities, but can have the following significant consequences for Confluence's functionality:

  • Office Connector is being disabled automatically (dependency to the WebDAV plugin):
    Microsoft Office documents can no longer be imported to, displayed or edited in Confluence.
  • WebDAV Plugin:
    WebDAV clients can no longer access or edit Confluence content.
  • Widget Connector:
    Youtube, Twitter, Vimeo, and Google Calendar embeds and likely content from other external sources can no longer be displayed. 
  • Potentially more functionality and apps may be affected when they rely on these two apps, but which we haven't yet identified.

Please contact us if you want us to disable these apps after carefully consideration of the impact. Alternatively you can disable the apps yourself.

WARNING

After the update, you can manually enable all of the apps again. You can do this in the same way as you disabled them described below, but select Enable instead.

When activating make sure that the Office Connector app needs to be enabled additionally and at last, as it depends on the WebDAV plugin.

The following apps must be enabled:

  • Widget Connector
  • WebDAV plugin
  • Office Connector




How do I disable the apps?

Demonstration

Here is a quick video tutorial showing you how to disable the plugins yourself: https://cl.ly/4ccbf8d1f680

Open the Confluence Administration area and select "Manage Apps".

Select All apps from app selection list.

To the left of the app selection list, enter "Widget Connector" in the search field and search for it. When the app appears in the search results, click on it to see the app information and click Disable. Once the first app has been disabled, repeat the process for the "WebDAV" app.


  • No labels