Dear Atlassian-Team (and possibly community),
due to multiple reasons we can not update our Jira and Confluence instances right away and need to further evaluate risk and consequences to make a decision on how to proceed.
As for now I am in desperate need for more information on how the vulnerability can be exploited by a user in Jira or Confluence and consequences this could have in a worst case scenario.
So to give this more context...
What do users have to do to (accidentally) exploit the vulnerability inside Jira Core, Service Management and Confluence?
As mentioned in the FAQ:
"A user must be able to post content in order for these characters, and potentially malicious code, to be introduced."
- What does this mean exactly? Create a issue on the customer portal? Publish or edit an article in Confluence?
And what could be worst possible outcome? Our instance doesn't have access to the internet is therefor only used by employees. The same questions go for Confluence, which also isn't connected to the internet.
Thank you and have a nice weekend!
Best regards,
Thomas