https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24998
https://nvd.nist.gov/vuln/detail/CVE-2023-24998
Still waiting for an "Official" response from Atlassian.
We've found the library present in Jira DC and Bamboo installs. In searching Atlassian.com it seems like the BitBucket team are the only ones to address this CVE to date.
Community moderators have prevented the ability to post new comments.
We need the workaround ASAP. This is stalling our work activities.
Looking for response to this too please!
Unofficial response since it's coming from me...
I opened a support ticket and was informed that Jira 9.6.1, 9.7 and LTS 9.4.4 should include a fix (upgraded Tomcat).
Just in case other folks are looking for more information. :)
Community moderators have prevented the ability to post new comments.