Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Is Macrosuite affected by the remote code execution (RCE) vulnerability of Log4j?

Cp panel macro
data%7B%22components%22%3A%5B%5D%2C%22titleAlignment%22%3A%22left%22%2C%22contentAlignment%22%3A%22left%22%2C%22title%22%3A%22Is%20Macrosuite%20effaced%20by%20the%20remote%20code%20execution%20(RCE)%20vulnerability%20affecting%20Log4j%3F%22%2C%22titleColor%22%3A%22%23172b4d%22%2C%22titleContainerColor%22%3A%22%23ffffff%22%2C%22background%22%3A%22%23ffffff%22%2C%22borderColor%22%3A%22%230052CC%22%2C%22borderRadius%22%3A4%2C%22borderType%22%3A%22solid%22%2C%22icon%22%3A%22%22%7D

No, Caelor customers are not vulnerable, and no action is required. This vulnerability has been mitigated for all Caelor cloud products previously using vulnerable versions of Log4j.

Security is a very important to Caelor. Therefore Caelor complies with the highest security standards. That's why Marcosuite is Cloud Fortified Certified. This is Atlassian's highest standard for cloud apps. More Information about Cloud Fortified can be found here.

...

What sort of data is collected, and what happens with that data?

...

data%7B%22components%22%3A%5B%5D%2C%22titleAlignment%22%3A%22left%22%2C%22contentAlignment%22%3A%22left%22%2C%22title%22%3A%22Is%20Macrosuite%20effaced%20by%20the%20remote%20code%20execution%20(RCE)%20vulnerability%20affecting%20Log4j%3F%22%2C%22titleColor%22%3A%22%23172b4d%22%2C%22titleContainerColor%22%3A%22%23ffffff%22%2C%22background%22%3A%22%23ffffff%22%2C%22borderColor%22%3A%22%230052CC%22%2C%22borderRadius%22%3A4%2C%22borderType%22%3A%22solid%22%2C%22icon%22%3A%22%22%7D

...

MacroSuite stores the installation information that Atlassian is

...

providing. This data is needed to identify a client but does not indicate or expose any user data. Additionally, we are tracking usage information of our product (e.g., which macro types are being used). However, we are not collecting any contextual information around our macros: we don’t know which images you are using in macros, the name of your Confluence pages, their authors/editors, or any content on them. At no point do we collect any personally identifiable information.

Where is the collected data being stored?

...

data%7B%22components%22%3A%5B%5D%2C%22titleAlignment%22%3A%22left%22%2C%22contentAlignment%22%3A%22left%22%2C%22title%22%3A%22Is%20Macrosuite%20effaced%20by%20the%20remote%20code%20execution%20(RCE)%20vulnerability%20affecting%20Log4j%3F%22%2C%22titleColor%22%3A%22%23172b4d%22%2C%22titleContainerColor%22%3A%22%23ffffff%22%2C%22background%22%3A%22%23ffffff%22%2C%22borderColor%22%3A%22%230052CC%22%2C%22borderRadius%22%3A4%2C%22borderType%22%3A%22solid%22%2C%22icon%22%3A%22%22%7D

...

We are using the Google Cloud Platform to maintain our Connect applications. Data of all used services are located in regions or regions within the European Union (Belgium, Netherlands, Zurich, Frankfurt, Finland, or Warsaw). Therefore EU jurisdiction applies. For more information, see: https://cloud.google.com/compute/docs/regions-zones. Our Forge apps rely on Atlassian's data residency features. We do not store any sensitive customer information like this.

Which data security protocols in relation to data breaches are in place?

...

...

data%7B%22components%22%3A%5B%5D%2C%22titleAlignment%22%3A%22left%22%2C%22contentAlignment%22%3A%22left%22%2C%22title%22%3A%22Is%20Macrosuite%20effaced%20by%20the%20remote%20code%20execution%20(RCE)%20vulnerability%20affecting%20Log4j%3F%22%2C%22titleColor%22%3A%22%23172b4d%22%2C%22titleContainerColor%22%3A%22%23ffffff%22%2C%22background%22%3A%22%23ffffff%22%2C%22borderColor%22%3A%22%230052CC%22%2C%22borderRadius%22%3A4%2C%22borderType%22%3A%22solid%22%2C%22icon%22%3A%22%22%7D

We do not collect any sensitive and/or personally identifiable information. All captured information is stored on highly secure Google servers located in Europe. In an unlikely event of a data breach, we will be informed by Google and pass this information on to our clients.

What happens if I don't install the new update because I don't want to pay for one app or both apps?

Cp panel macro
data%7B%22components%22%3A%5B%5D%2C%22titleAlignment%22%3A%22left%22%2C%22contentAlignment%22%3A%22left%22%2C%22title%22%3A%22%22%2C%22titleColor%22%3A%22%23000000%22%2C%22titleContainerColor%22%3A%22%23ffffff%22%2C%22background%22%3A%22%23ffffff%22%2C%22borderColor%22%3A%22%230052CC%22%2C%22borderRadius%22%3A4%2C%22borderType%22%3A%22solid%22%2C%22icon%22%3A%22%22%7D

Unfortunately, not installing the update will mean that your feature set will not be enhanced and optimized. Updates allow us to provide you, our user, with a better user experience when using the app. You can continue to use the version free of charge up to and including October 15. After that, you can use the functions of the app only after upgrading to the latest version.

When will the new price be introduced?

Cp panel macro
data%7B%22components%22%3A%5B%5D%2C%22titleAlignment%22%3A%22left%22%2C%22contentAlignment%22%3A%22left%22%2C%22title%22%3A%22%22%2C%22titleColor%22%3A%22%23000000%22%2C%22titleContainerColor%22%3A%22%23ffffff%22%2C%22background%22%3A%22%23ffffff%22%2C%22borderColor%22%3A%22%230052CC%22%2C%22borderRadius%22%3A4%2C%22borderType%22%3A%22solid%22%2C%22icon%22%3A%22%22%7D

For all new users, the new price will be applied from the first of October. All existing users will have until October 15 to update. Until then, the app can still be used for free. After that, you can use the functions of the app only after upgrading to the latest version.

Why is the app now chargeable?

Cp panel macro
data%7B%22components%22%3A%5B%5D%2C%22titleAlignment%22%3A%22left%22%2C%22contentAlignment%22%3A%22left%22%2C%22title%22%3A%22%22%2C%22titleColor%22%3A%22%23000000%22%2C%22titleContainerColor%22%3A%22%23ffffff%22%2C%22background%22%3A%22%23ffffff%22%2C%22borderColor%22%3A%22%230052CC%22%2C%22borderRadius%22%3A4%2C%22borderType%22%3A%22solid%22%2C%22icon%22%3A%22%22%7D

Since we launched MacroSuite, we have not charged a price for our unique formatting app. Till today, we have added many more features to our apps that where requested by you, our users. With today's release, we are again releasing new features that will help you have even more fun working in Confluence.

A side effect of this is an increased demand for support and development teams to keep things running smoothly in more complex environments. Now it is time to adjust the pricing to reflect the amount of development and support that has gone into all of the new and improved features. On 1st of October, 2021 prices will go up to the levels outlined in the Atlassian Marketplace.

What new features were added with the release on 10/01/2021?

...

data%7B%22components%22%3A%5B%5D%2C%22titleAlignment%22%3A%22left%22%2C%22contentAlignment%22%3A%22left%22%2C%22title%22%3A%22%22%2C%22titleColor%22%3A%22%23000000%22%2C%22titleContainerColor%22%3A%22%23ffffff%22%2C%22background%22%3A%22%23ffffff%22%2C%22borderColor%22%3A%22%230052CC%22%2C%22borderRadius%22%3A4%2C%22borderType%22%3A%22solid%22%2C%22icon%22%3A%22%22%7D

The following functions were integrated within the new update:

...

Within the macro "Button" it is now possible to design the buttons in more detail (size, border, type). In addition, the user has an improved link selection for referring to further content

...

The Page Divider now maps the selection of page divider types and offers the option to use different colours for symbol or text

...

The page countdown now has different countdown timer types. In addition, time zone support has been implemented, which can also be integrated in different colours and fonts on Confluence

...

The macro image carousel has been extended with a new thumbnail navigation, the function of automatic playback and an improved image selection. In addition, the user can now define the height and width of the carousel as desired and determine the image zoom type

...

In the Confluence Editor, the option to use many native Confluence functions has now been integrated

...

Is Macrosuite affected by the remote code execution (RCE) vulnerability of Log4j?

No, Caelor customers are not vulnerable, and no action is required. This vulnerability has been mitigated for all Caelor cloud products previously using vulnerable versions of Log4j.

Security is very important to Caelor. Therefore Caelor complies with the highest security standards. That's why MarcoSuite is Cloud Fortified Certified. This is Atlassian's highest standard for cloud apps. More Information about Cloud Fortified can be found here.