Dear Atlassian Team
On this page there's a brief message that no Atlassian product is impacted by CVE-2018-11776. However, to keep our Risk & Governance stakeholders suitably informed, would it please be possible for Atlassian to release an advisory confirming there's no impact and positively confirming that this is true for Bamboo as well?
It would be very useful to have official comms on this (vs a comment on a forum).
Given this is an RCE (remote code exection) vuln organizations with automated scanners are flagging Bamboo as vulnerable. An advisory will help ensure that teams using Bamboo can continue to do so confidently.
Thank you!