Missed Team ’24? Catch up on announcements here.

×
Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Is Crucible/Fisheye v4.8.13/4.8.14 vulnerable to CVE-2022-22978?

Kirk Williams August 9, 2023

Our Tenable scan has flagged our recent upgrade to Crucible/Fisheye 4.8.13/4.8.14 for containing a Sprint Security verision prior to 5.5.7 or 5.6.x prior to 5.6.4.

Docker container running on RHEL7.

Flagged file:

/var/lib/docker/overlay2/xxxx/merged/atlassian/apps/crucible/lib/spring-security-core-3.2.5.RELEASE.jar.

It is recommended the version be upgraded from 3.2.5 to 5.5.7.

Is Crucible impacted by this CVE?  Will there be an update to the latest image for this issue in the near future?

0 answers

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
VERSION
4.8.14
TAGS
AUG Leaders

Atlassian Community Events