CVE-2018-13400, CVE-2018-13401 & CVE-2018-13402 are fixed in version 7.11.3, as per the following link.
https://jira.atlassian.com/browse/JRASERVER-68138?jql=labels%20%3D%20CVE-2018-13400
However, the Jira 7.11 release notes page has no reference to version 7.11.3.
https://confluence.atlassian.com/jirasoftware/jira-software-7-11-x-release-notes-952600888.html
Any help with this?
Hi @sri pinninti,
There is indeed no 7.11.3 release. I noticed that the issue has also been fixed in 7.12.3, which is the current latest version.
This is because it was flagged for release in 7.11.3 by the developers originally, but they moved on to 7.12 instead.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thank you. Atlassian confirmed that the version doesn't exist.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.