Our server has commons-text.1.6.jar in the plugins but also in the WEB-INF/lib.
Thank you.
@Shay Keidar You can download v.1.10 from the Apache web site Commons Text – Download Apache Commons Text and replace your outdated version with the new one in the WEB-INF/lib. Do it in non-production environment first to make sure it won't break anything. In our case, neither JIRA and Confluence had any issues after the update.
Atlassian is always behind with updating third-party components, and if the finding is critical, it's probably better to update it yourself and not rely on any security advisory.
Hi @Shay Keidar ,
welcome to the Atlassian community!
Atlassian team is currenlty investigationg about that security issue. Please check updates here https://www.atlassian.com/trust/security/advisories
Hope this helps,
Fabio
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.