I need to get an announcement about: cve-2022-23302, cve-2022-23305, cve-2022-23307
Hi @lei ,
A common method for getting information about CVEs when Atlassian have not published a security advisory is to check our public Jira instance. Here is a link to a search for the 3 CVEs you mentioned .
Please see our Security Bug Fix Policy for more information about the questions you have raised.
Also note that @Nic Brough -Adaptavist- is not an Atlassian employee - the Community Leader designation next to his name indicates that he has moderator privileges here on Community, which is a public forum. Atlassian employees are indicated by an "Atlassian Team" lozenge next to their name.
I'll also mention that the Trust & Security group is the place where you will see official messages from Atlassian's Security team here on Community. Atlassian's Security team will also utilize email to notify administrators of any security advisories we have published.
Thanks,Daniel Eads | Atlassian Support
The best thing to do with CVE reports is to subscribe to the updates on the CVE reporting site that you prefer.
I think Atlassian are better than most organisations when there is a security problem. (If we go to the extremes, Atlassian announce security issues within weeks, but we're still waiting for MS to announce "Windows is insecure" 40 years after the insecure release of 3.1)
If you want info about these reports of insecurity, look at the independent reports. Do not trust the vendor just because they get other stuff right. Read the CVE, then read what the vendor says. Maybe subscribe to the vendor's security feed.
JIRA software 7.2.xx is facing shutdown due to log4j(cve-2022-23302, cve-2022-23305, cve-2022-23307) in our company
So we need a statement that it's okay or not
How should I prove it?
If it's okay, could you please give user a proof
If it has a problem, please tell user how to solve it
You'll need to work it out from the CVEs - they have not been evaluated yet so no one has done the work to say whether any particular application may be affected.
Do you have a time plan?
Thank you very much. I'll make a request now
Here is a link to a search for the 3 CVEs you mentioned .
Actually, I'll note that search link currently just leads to issue JRASERVER-62838, which doesn't discuss the first CVE (CVE-2022-23302) at all, and only started discussing the latter two CVEs (CVE-2022-23305 and CVE-2022-23307) a few hours ago.
It looks like you're new here. Sign in or register to get started.