Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

CVE Alerts for Plugin Vendors?

Lawrence
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
August 31, 2023

Does anyone know a method to automatically monitor CVEs from Plugin vendors? Right now we just manually perform searches for the app/vendor and version, but as we grow this is becoming more and more of tedious task.

Anyone have any suggestions?

 

Thanks in advance!

1 answer

1 accepted

1 vote
Answer accepted
Mirek
Community Champion
August 31, 2023

Hi @Lawrence 

Unfortunately there is no an easy way to get this automatically. Every vendor has his own way to track security issues and mostly including this information on their site or documentation. So it is a matter of how this is stored.

I think thank maybe using a script and scanning in description by plugin name on portals that gather information about CVE might be the way but not always it is clear enough to be sure that we are getting all. 

I would start by listing all plugins that you use and adding information where those security announcements are showing then try to figure out how to gather this automatically. Maybe all are using Confluence or any other system that allows getting information using REST API so a script that would get this directly from their sites might also work. 

Lawrence
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
September 1, 2023

This is what we started to think would be the best course of action.

Thanks so much!

Like Mirek likes this

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
VERSION
9.4.9
TAGS
AUG Leaders

Atlassian Community Events