Security Advisories & Errata

ISMS for Confluence

Security Update: ISMS for Confluence 1.1.0

Updated recursive dependency to fix several vulnerabilities.

Affected Products:

  • ISMS for Confluence
    • Affected Versions: Versions from 1.0.0 onward and below 1.1.0
    • Fix Version: 1.1.0

Exploitability requires manual user interaction of a confluence system administrator introducing data from an untrusted source.

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H/E:U (7.6)

CVE IDs:

CVE-2021-20190, CVE-2020-36183, CVE-2020-36182, CVE-2020-36180, CVE-2020-36179, CVE-2020-36189, CVE-2020-36188, CVE-2020-36187, CVE-2020-36186, CVE-2020-36185, CVE-2020-36184, CVE-2020-36181, CVE-2020-35728, CVE-2020-35491, CVE-2020-35490, CVE-2020-25649, CVE-2020-24750, CVE-2020-24616, CVE-2020-14195, CVE-2020-14060, CVE-2020-14062, CVE-2020-14061, CVE-2020-11620, CVE-2020-11619, CVE-2020-11113, CVE-2020-11112, CVE-2020-11111, CVE-2020-10969, CVE-2020-10968, CVE-2020-10673, CVE-2020-10672, CVE-2020-9548, CVE-2020-9547, CVE-2020-9546, CVE-2020-8840

(FasterXML jackson-databind 2.x before 2.9.10.x mishandles the interaction between serialization gadgets and typing)

Date Issued: 2021-09-07