We are Using Crowd Server and current as per internal security scan it has detected Spring Framework Remote Code Execution (RCE) Vulnerability (Spring4Shell) vulnerability. As per the latest CVE Report (https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement#overview) it was mentioned that Spring Framework versions 5.3.0 to 5.3.17, 5.2.0 to 5.2.19, and older versions are impacted with the vulnerability.
We have upgraded Crowd Server to the latest version 4.4.1 and found that still Spring Framework version is 5.3.7 & 5.5.1.
Can you please let us if there are any patches which is or will be released to fix this vulnerability.
Hi @Avijit Chakraborty
At the current moment, Crowd use impacted versions of Spring but is not vulnerable to any known exploit. More details here: https://confluence.atlassian.com/kb/faq-for-cve-2022-22965-1115149136.html
Hi everyone, We’re always looking at how to improve Confluence and customer feedback plays an important role in making sure we're investing in the areas that will bring the most value to the most c...
Connect with like-minded Atlassian users at free events near you!Find an event
Connect with like-minded Atlassian users at free events near you!
Unfortunately there are no Community Events near you at the moment.Host an event
You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events