The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Is Crowd server 5.2.1 vulnerable to CVE-2023-50164

Adam Frankowski
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
December 12, 2023

Hi,

According to CVE-2023-50164, Apache Struts has a Remote Code Execution vulnerability, present in version 2.5.32 of their library.

For more details see the following:
- https://nvd.nist.gov/vuln/detail/CVE-2023-50164
- https://cwiki.apache.org/confluence/display/WW/s2-066

We have conducted a security scan of our systems which has detected Apache Struts 2.5.32 JAR files in Crowd Server 5.2.1.

Our question is simple, is Atlassian Crowd (Server Edition) vulnerable to CVE-2023-50164?  If it is, when will a fix be released?

Thank you to anyone who responds,

Adam

1 answer

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

1 vote
Geoff Seeley
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
December 18, 2023

This details a patched 2.5.33 drop-in-replacement:

https://lists.apache.org/thread/yh09b3fkf6vz5d6jdgrlvmg60lfwtqhj

Obviously an official update from Atlassian would be best but this can make do until then as I suspect the holidays are going to delay vendor responses to this CVE.

DEPLOYMENT TYPE
SERVER
TAGS
AUG Leaders

Atlassian Community Events