Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,300,187
Community Members
 
Community Events
165
Community Groups

confluence 7.12.4 CVE-2022-22965 vulnerability

Hi , 

seems conflunce with version 7.12.4 has CVE-2022-22965 vulnerability, which shows as below:

 

Path /confluence/WEB-INF/lib/atlassian-plugins-spring-5.3.11.jar
Installed version : 5.3.11 Fixed version : 5.3.18
Path : /confluence/WEB-INF/lib/atlassian-spring-2.0.8.jar
Installed version : 2.0.8 Fixed version : 5.2.20
Path : /confluence/WEB-INF/lib/sal-spring-4.1.0.jar
Installed version : 4.1.0 Fixed version : 5.2.20
Path : /confluence/WEB-INF/lib/spring-core-5.1.18.RELEASE.jar Installed version :
5.1.18.RELEASE Fixed version : 5.2.20
Path :
/confluence/synchrony-proxy/WEB-INF/lib/spring-core-5.1.18.RELEASE.jar
Installed version : 5.1.18.RELEASE Fixed version : 5.2.20

 

how can we remediate it .

can we upgrade confluence to  solve this?

 

1 answer

1 accepted

1 vote
Answer accepted

Hi @Mengmeng Yu ,

currently, Atlassian team is investigation about this security issue (https://community.developer.atlassian.com/t/attention-cve-2022-22965-spring-framework-rce-investigation/57172). You will find the official patch/workaround at the end of that investigation through the Atlassian Security  Advisories https://www.atlassian.com/trust/security/advisories

Hope this helps,

Fabio

Kishan Sharma Community Leader Apr 19, 2022

Hi @Mengmeng Yu 

Please also keep an eye on Atlassian's FAQ for CVE-2022-22965 for new information.

Like # people like this

Thanks for you both help. this is quite helpful.

Like Kishan Sharma likes this

Suggest an answer

Log in or Sign up to answer
TAGS
Community showcase
Published in Confluence

An update on Confluence Cloud customer feedback – June 2022

Hi everyone, We’re always looking at how to improve Confluence and customer feedback plays an important role in making sure we're investing in the areas that will bring the most value to the most c...

356 views 2 9
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you