Atlassian, is Confluence Server vulnerable?
https://www.cyberkendra.com/2022/03/springshell-rce-0-day-vulnerability.html
https://www.bleepingcomputer.com/news/security/new-spring-java-framework-zero-day-allows-remote-code-execution/
https://threatpost.com/critical-rce-bug-spring-log4shell/179173/
https://bugalert.org/content/notices/2022-03-30-spring.html
Hi @SSP Admins ,
Welcome to Atlassian community.
At this moment there is no update on this . You can bookmark the below URL where Atlassian keeps updating the vulnerablities and its impact info.
I hope above info helps. Have a good day!
Thanks,
Srinath T
Hi @SSP Admins
later the month there was a knowledge base entry made which talks about the vulnerability more in details - you could review it, in case the topic is still relevant to your team:
The corresponding bug on JAC was: https://jira.atlassian.com/browse/CONFSERVER-78586
Regards,Daniel
It looks like you're new here. Sign in or register to get started.