Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

CVE-2019-3398 impact on client-api jar versions

Prakash Mehta
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
May 29, 2019

Following CVE's are reported on confluence-rest-client-6.9.3.jar and confluence-java-api-6.14.2.jar by our SCA(Software Composition Analysis) tool : 

  • CVE-2019-2298
  • CVE-2018-20237
  • CVE-2019-3395
  • CVE-2019-3396 

Based on the security advisory(https://confluence.atlassian.com/doc/confluence-security-advisory-2019-04-17-968660855.html) it appears that vulnerability exists only on server components and organizations using cloud version are not impacted. So with that explanations can we assume the above CVE's are false positive reports for confluence-rest-client-6.9.3.jar and confluence-java-api-6.14.2.jar

1 answer

0 votes
Stephen Sifers
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
June 3, 2019

Hello Prakash and welcome to the Community!

The information you provided is specific to Confluence Server installs and as you specified are not relevant to Confluence cloud products. The har files you included are also specific to Server installs (note the 6.9.3 and 6.14.2 versions) as the version in the filename reflects that of a Confluence server version.

A follow-up question I would like to ask is, how are you interacting with the listed jar files? It could be possible you’re using an Atlassian SDK which includes these files and we want to ensure we’re properly addressing your concern.

We look forward to your response to ensure your security concerns are addressed.

Regards,
Stephen Sifers

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events