We are using Atlassian SDK to develop a Custom Jira Plugin in which we are also using Atlassian-spring-scanner-annotation dependency. After building the Jira Plugin, we have noticed that the following spring-related dependencies are getting packaged with the Plugin:
Can anyone please clarify if these Spring related dependencies are vulnerable to Spring CVEs (CVE-2022-22963, CVE-2022-22965)? If vulnerable, is there any possible workaround to fix it?
Hi @[deleted] ,
this page should clarify your doubt https://confluence.atlassian.com/kb/faq-for-cve-2022-22965-1115149136.html
Hope this helps,
Fabio
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.