Technical Forum
Ask questions. Discover Answers.
cancel
Showing results for 
Search instead for 
Did you mean: 
Custom Alert Banner

Atlassian Confluence Critical CVE-2021-26084 Mitigation with F5 ASM / F5 WAF

samstep
Cirrocumulus
Cirrocumulus

The Confluence CVE-2021-26084 critical vulnerability is in active exploitation, quick mitigation on ASM is to add the following URL to the Disallowed URL:

/pages/createpage-entervariables.action

Make sure that you enable blocking on the 'Ilegal URL' violation.

Patch/update your Confluence:

Link to Confluence Security Advisory - 2021-08-25:

https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html

1 REPLY 1

samstep
Cirrocumulus
Cirrocumulus

This is how attackers currently bypass WAF:

https://twitter.com/Jok3rDb/status/1434099427862482952

The "quick mitigation" on ASM is to

Disallow URL:

/pages/createpage-entervariables.action