Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,298,766
Community Members
 
Community Events
165
Community Groups

Spring Framework Remote Code Execution (RCE) Vulnerability (Spring4Shell)

We are Using Crowd Server and current as per internal security scan it has detected Spring Framework Remote Code Execution (RCE) Vulnerability (Spring4Shell) vulnerability. As per the latest CVE Report (https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement#overview) it was mentioned that Spring Framework versions 5.3.0 to 5.3.17, 5.2.0 to 5.2.19, and older versions are impacted with the vulnerability. 

We have upgraded Crowd Server to the latest version 4.4.1 and found that still Spring Framework version is 5.3.7 & 5.5.1. 

Can you please let us if there are any patches which is or will be released to fix this vulnerability. 

1 answer

Hi @Avijit Chakraborty 

At the current moment, Crowd use impacted versions of Spring but is not vulnerable to any known exploit. More details here: https://confluence.atlassian.com/kb/faq-for-cve-2022-22965-1115149136.html

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
TAGS
Community showcase
Published in Confluence

An update on Confluence Cloud customer feedback – June 2022

Hi everyone, We’re always looking at how to improve Confluence and customer feedback plays an important role in making sure we're investing in the areas that will bring the most value to the most c...

233 views 1 4
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you