Missed Team ’24? Catch up on announcements here.

×
Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Fix regarding cve-2022-22970 / cve-2022-22971

Markus July 26, 2022

Dear all,

currently our jira service desk is availavle over the world-wide-web.
Internal vulnerability scans showed that cve-2022-22970 / cve-2022-22971 is affected to the current installed JIRA SD 4.20.11 version.

/opt/atlassian/jira/atlassian-jira/WEB-INF/lib/spring-core-5.3.19.jar

Is it anyhow planed to fix this issue?
Do you have any workaround?

2 answers

0 votes
Tushar Gohel October 3, 2022

Hi @Markus 

 

Here is the suggestion where you can vote to get it fixed early --> https://jira.atlassian.com/browse/JSWSERVER-21486

 

Thanks,

Tushar

0 votes
Joseph Chung Yin
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
July 26, 2022

@Markus -

The last security alert issued in July 2022 by Atlassian was - https://confluence.atlassian.com/security/multiple-products-security-advisory-cve-2022-26136-cve-2022-26137-1141493031.html

You need to contact Atlassian Support directly to obtain the proper support and assistance (https://support.atlassian.com) on your cve references.

Best, Joseph Chung Yin

Jira/JSM Functional Lead, Global Infrastructure Applications Team

Viasat Inc.

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
TAGS
AUG Leaders

Atlassian Community Events