Our security scanning software is complaining about Apache Commons Text within our Confluence installation.
When will Atlassian be posting guidance/remediation on this issue?
Hi @Rusty Rusty ,
Atlassian is currently investigating on that. Btw, a security alert will be reported here https://www.atlassian.com/trust/security/advisories and all of us will be notified via email if Atlassian has some communication.
Hope this helps,
Fabio
Is there already any public announcement by Atlassian for this? In the advisories there is nothing that mentions this CVE and we have been asked by our Security Team to check this for our Confluence installation as it contains the affected Commons Text versions. As we are using a Starter License there is no other way for us to request support than this community. Any information if Confluence 7.19.0 is vulnerable for this CVE would be appreciated.
If anyone else searches for an answer, this was published yesterday evening: [CONFSERVER-81048] Upgrade Apache Commons-text for CVE-2022-42889 - Create and track feature requests for Atlassian products.
It looks like you're new here. Sign in or register to get started.