Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,361,124
Community Members
 
Community Events
168
Community Groups

Can I update only Struts on a Crowd 4.2 server due to CVE-2020-17530?

It seems Crowd 4.2 uses Struts version 2.5.17 and CVE-2020-17530 states that anything less that 2.5.26 is vulnerable to remote code execution attacks. I do not know if forced OGNL evaluation is used or not but I am being told to update. Is there a documented way to update Struts only on Crowd servers?

0 answers

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
TAGS
Community showcase
Published in Jira

Online AMA this week: Your project management questions answered by Jira Design Lead James Rotanson

We know that great teams require amazing project management chops. It's no surprise that great teams who use Jira have strong project managers, effective workflows, and secrets that bring planning ...

201 views 1 6
Read article

Atlassian Community Events