In regard to CVE-2023-22515, is this relevant to both JIRA and Confluence?

Joe Kensinger October 13, 2023

According to the IAVM site, this CVE is relevant only to Confluence servers and mentions nothing of JIRA.  Is there a patch update for JIRA servers related to this CVE?

2 answers

2 accepted

1 vote
Answer accepted
Robert Wen_Cprime_
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
October 13, 2023

Hello @Joe Kensinger ! Welcome to the Atlassian Community!

No patch version for Jira.  Because the CVE affects Confluence, the patch versions are for Confluence Server/Data Center.

Joe Kensinger October 13, 2023

Appreciate the reply.  I will share this information with my team.

0 votes
Answer accepted
Dan Breyen
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
October 13, 2023

Hi Joe, I found this FAQ from Atlassian, it doesn't mention Jira either: faq-for-cve-2023-22515 

I did a quick google search (well Duck-Duck-Go) and didn't find any references to Jira either.

You could check with support (support.atlassian.com/contact) to know for sure.

Hope that helps.

Joe Kensinger October 13, 2023

Appreciate the reply.  I will share this information with my team.

Suggest an answer

Log in or Sign up to answer