Regarding the recently announced critical security advisory for CVE-2022-0540 regarding Authentication bypass in JIRA Server, is this still a critical vulnerability if the JIRA instance is confined to the internal network only and is not accessible from the internet?