Atlassian has today emailed us alerting us to the following:
Jira Service Management Cloud, Data Center and Server
• CVE‑2023‑22523 – RCE vulnerability in Assets Discovery app
• CVE‑2022‑1471 – SnakeYAML library RCE vulnerability impacts multiple products (Data Center and Server only)
Jira Software and Jira Core Data Center and Server, Automation for Jira apps
• CVE-2022-1471 – SnakeYAML library RCE vulnerability impacts multiple products
However, doing the following searches at jira.atlassian.com
found nothing
For the next CVE:
also found nothing
and doing a general internet search across atlassian.com:
site:atlassian.com CVE‑2023‑22523
found nothing,
and for: