Hi,
I have a question about how to mitigate the CVE-2022-43782 (Critical security misconfiguration vulnerability) vulnerability.
Crowd Security Advisory (November 2022) | Crowd Data Center and Server 5.0 | Atlassian Documentation
1. It seems that only the crowd application is targeted, is it correct? (excluding the jira application added by the user)
2. Should I remove the domain address or 127.0.0.1 entered in Remote addresses?
Thank you
Reviewing old questions then came across yours.
I am sure by now this is no longer an issue.
Usually the vulnerability specifies which application is affected. If no other application was mentioned that means it is safe and you only have to follow the steps suggested by Atlassian to fix the vulnerability like in your case (Crowd).
All the best,
Fadoua
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.