To exploit the following prerequisites must be met:
The SAML Single Sign On-addon is installed in version 0.14.7 or older
The attacker has valid access with a userid which can be turned into the victim user's userid by cutting off characters in the end
What You Need to Do
Upgrade to SAML Single Sign On (SSO) Version 0.15.3 or higher.
For all current Confluence and Jira Versions that are not end of Life yet, either a 0.15.x or a 2.x Version is available.
Jira version 0.11.4 has been added to the Marketplace for very old end of Life Jira Installations.
Confluence version 0.12.3.3 has been added to the Marketplace for very old end of Life Confluence Installations.
If you are running older versions of Jira or Confluence and cannot update, please raise a support request via our Support Portal.
Support
If you have questions or concerns regarding this advisory, please raise a support request via our Support Portal.