The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Questions about how to mitigate vulnerability (CVE-2022-43782)

JooHyun Park
November 21, 2022

Hi,

I have a question about how to mitigate the CVE-2022-43782 (Critical security misconfiguration vulnerability) vulnerability.

Crowd Security Advisory (November 2022) | Crowd Data Center and Server 5.0 | Atlassian Documentation

1. It seems that only the crowd application is targeted, is it correct? (excluding the jira application added by the user)

2. Should I remove the domain address or 127.0.0.1 entered in Remote addresses?

Thank you

1 answer

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

0 votes
Tinker Fadoua
Community Champion
April 11, 2026

Hi @JooHyun Park 

Reviewing old questions then came across yours.

I am sure by now this is no longer an issue.

Usually the vulnerability specifies which application is affected. If no other application was mentioned that means it is safe and you only have to follow the steps suggested by Atlassian to fix the vulnerability like in your case (Crowd).

All the best,

Fadoua

TAGS
AUG Leaders

Atlassian Community Events