Are Jira Cloud products affected by CVE-2024-3094 xz/liblzma described at the following links?
Description:
Cloud products generally are not affected because as a SaaS product, Atlassian takes care of the fixes when a CVE emerges.
Hi Robert,
Thanks for your answer. However, if I have correctly understood, Atlassian release a Security Bulletin (https://www.atlassian.com/trust/security/advisories) on the third Tuesday of every month, so we need to wait till 16th April to know if a patch has been applied (in case it was needed).
Due to the criticality of this vulnerability I would have expected an official communication from Atlassian in short time to let the customers know that their products were not affected or that the vulnerability was promptly fixed...
"Stable versions of most Linux distributions were not affected."
I'd be very surprised if Atlassian had updated the OS in their Cloud hosts recently enough to run into this problem.
But yes, it would be helpful to have an official communication from Atlassian that says "no worries, mates!"
It looks like you're new here. Sign in or register to get started.