CVE-2023-51467 describes a vulnerability in Apache OfBiz. While researching the matter, Jira keeps showing up as a product/service which leverages Apache OfBiz. We use the cloud version of Jira and Confluence. I haven't seen anything in any of the security nor support sections regarding it.
Is Atlassian vulnerable to this exposure? What are the timelines for addressing the vulnerability?
Hi @Mark Neustadt welcome to the community! I did a quick google search on the issue and didn't see anything regarding Atlassian's response yet.
You may want to open a Support ticket with Atlassian (support.atlassian.com/contact) to get a firmer answer on this question.
I know Atlassian does monitor the community posts, but you might get a quicker response directly through support.
Here's a link to the Community Group regarding Security Issues that you may wish to subscribe to: TrustandSecurity
There's a bunch of links regarding Security Issues, and at least one specific to the cloud as well.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.