The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Affects CVE-2022-23529 (JWT) atlassian products?

Jörg Werner
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
January 11, 2023

3 comments

Comments for this post are closed

Community moderators have prevented the ability to post new comments.

Ste Wright
Community Champion
January 11, 2023
Like # people like this
Alex Koxaras -Relational-
Community Champion
January 11, 2023

Hi @Jörg Werner 

Currently we have no formal announcement from Atlassian. I would indeed take a look at the links provided by Stephen and keep a look out at the community as well.

David at David Simpson Apps
Atlassian Partner
January 11, 2023

Look for a formal announcement from Atlassian, however my findings are as follows:

This CVE is for jsonwebtoken <= 8.5.1.

  • Atlassian have written their own library for JWT (atlassian-jwt) which does not depend on jsonwebtoken, so likely this is what they use internally in their own apps*
  • Apps built on the Atlassian Connect Express (ACE) framework use atlassian-jwt and are therefore should not be affected
  • Running npm list -a on an ACE-based app's source code shows no dependency on jsonwebtoken

* I say "likely" here as I have no real way of knowing what they do internally, so again, look for a formal announcement from Atlassian.

Like # people like this

Comments for this post are closed

Community moderators have prevented the ability to post new comments.

TAGS
AUG Leaders

Atlassian Community Events