Hello @fernandavalverde ,
I can verify that we are not using the vulnerable framework.
The confusion came when Sonicwall posted an article falsely claiming Atlassian Jira and other products were also vulnerable.
Sonicwall looks to have taken the information from this page and concluded Jira is vulnerable with a misunderstanding in versioning.
We have contacted Prodsec, looking at the code in Jira DC, Jira Cloud, Confluence DC, and Confluence Cloud to confirm that WE ARE NOT USING THE VULNERABLE FRAMEWORK. Jira only uses a fork of Apache’s OfBiz Entity Engine module, which does not include the affected areas of code. Additionally, Confluence does not use the Entity Engine module at all.
Internally we are currently working with Crisis Comms to retract to Sonicwall blog that includes our products in the affected list but there will probably still be lingering articles out there that reference the report and incorrectly list our products in relation to this vulnerability.
Regards,
Earl
A Little more info on this including the initial Blog and reference docs, Noting These all concern ofbiz/webapp
which is not part of the repo used by the Atlassian Suite:
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.