Atlassian has published security advisory CVE-2022-26136, CVE-2022-26137 today, 20 JULY 2022. This advisory is in regards to and affects the Servlet Filter Dispatcher in multiple Server and Datacenter products; these vulnerabilities have already been resolved in the Atlassian Cloud Sites. The goal of this article is to help raise awareness for this critical vulnerability and to provide you a means to ask further questions about this in Community if needed.
Please review the complete advisory in Multiple Products Security Advisory - CVE-2022-26136, CVE-2022-26137 with our FAQ in FAQ for CVE-2022-26136 / CVE-2022-26137.
Is this issue limited to HTTP only or also affects HTTPS?
@J_Dan Garing
Great question, we have updated our FAQ to also answer this;
We use HTTPS/SSL, are we still vulnerable? Yes. HTTPS is HTTP with encryption (SSL/TLS) which helps secure content traveling between two points. Whether or not encryption is used doesn’t have any effect on how the vulnerability can be exploited.
Yes. HTTPS is HTTP with encryption (SSL/TLS) which helps secure content traveling between two points. Whether or not encryption is used doesn’t have any effect on how the vulnerability can be exploited.
Source: FAQ for CVE-2022-26136 / CVE-2022-26137 | We use HTTPS/SSL, are we still vulnerable?
Regards,Stephen Sifers
It looks like you're new here. Sign in or register to get started.