REF CVE-2023-51467
Hello @fernanda_valverde ,
I can verify that we are not using the vulnerable framework.
The confusion came when Sonicwall posted an article falsely claiming Atlassian Jira and other products were also vulnerable.
Sonicwall looks to have taken the information from this page and concluded Jira is vulnerable with a misunderstanding in versioning.
We have contacted Prodsec, looking at the code in Jira DC, Jira Cloud, Confluence DC, and Confluence Cloud to confirm that WE ARE NOT USING THE VULNERABLE FRAMEWORK. Jira only uses a fork of Apache’s OfBiz Entity Engine module, which does not include the affected areas of code. Additionally, Confluence does not use the Entity Engine module at all.
Internally we are currently working with Crisis Comms to retract to Sonicwall blog that includes our products in the affected list but there will probably still be lingering articles out there that reference the report and incorrectly list our products in relation to this vulnerability.
Regards,Earl
A Little more info on this including the initial Blog and reference docs, Noting These all concern ofbiz/webapp which is not part of the repo used by the Atlassian Suite:
ofbiz/webapp
Replaced direct null checks on username, password, and token with Uti… · apache/ofbiz-framework@fb51a0e
Replaced direct null checks on username, password, and token with Uti… · apache/ofbiz-framework@47e7959
Replaced direct null checks on username, password, and token with Uti… · apache/ofbiz-framework@d8b097f
Replaced direct null checks on username, password, and token with Uti… · apache/ofbiz-framework@e9bfc34
It looks like you're new here. Sign in or register to get started.