Following CVE's are reported on confluence-rest-client-6.9.3.jar and confluence-java-api-6.14.2.jar by our SCA(Software Composition Analysis) tool :
Based on the security advisory(https://confluence.atlassian.com/doc/confluence-security-advisory-2019-04-17-968660855.html) it appears that vulnerability exists only on server components and organizations using cloud version are not impacted. So with that explanations can we assume the above CVE's are false positive reports for confluence-rest-client-6.9.3.jar and confluence-java-api-6.14.2.jar
Hello Prakash and welcome to the Community!
The information you provided is specific to Confluence Server installs and as you specified are not relevant to Confluence cloud products. The har files you included are also specific to Server installs (note the 6.9.3 and 6.14.2 versions) as the version in the filename reflects that of a Confluence server version.
A follow-up question I would like to ask is, how are you interacting with the listed jar files? It could be possible you’re using an Atlassian SDK which includes these files and we want to ensure we’re properly addressing your concern.
We look forward to your response to ensure your security concerns are addressed.
Regards,
Stephen Sifers
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.