Hi,
as i can see in https://confluence.atlassian.com/security/multiple-products-security-advisory-cve-2022-26136-cve-2022-26137-1141493031.html our used jira & confluence versions are listed in "affected" and also in "fixed" version. So what is to do? Are we affected or not?
We are using confluence 7.13.7 and jira 8.20.7
Affected:
confluence 7.13.x < 7.13.7
or is the meaning "lower than 7.13.7 but not 7.13.7"?
jira 8.20.x < 8.20.10
Fixed:
Can anybody translate this table into simple version information like "fixed since x.x.xx"? As i can see in the changelog there is also no fix information about the cve in the last versions.
Best Regards
Manuel
Confluence is fixed since 7.13.7
Jira is fixed since 8.20.10
"x" is being used as a placeholder. For Confluence:
Affected 7.13.x < 7.13.7 means 7.13.0, 7.13.1, ..., 7.13.6
Fixed 7.13.x >= 7.13.7 means 7.13.7, 7.13.8, ...
For Jira:
Affected 8.20.x < 8.20.10 means 8.20.0, 8.20.1, ..., 8.20.9
Fixed 8.20.x >= 8.20.10 means 8.20.10, 8.20.11, ...
This placeholder make absolut no sense, but, however, thanks.
It looks like you're new here. Sign in or register to get started.