Today, I find that "spring2shell" volnerabilities in https://www.lunasec.io/docs/blog/spring-rce-vulnerabilities/ .
Does anyone know that this volnerabilities affect Atlassian products such like a Jira, Confluence?
Thank you,
Update:
Please see the latest FAQs posted over the weekend: https://confluence.atlassian.com/display/KB/FAQ+for+CVE-2022-22965
As always, you can monitor security vulnerabilities at the following link https://www.atlassian.com/trust/security/advisories
You can also report a vulnerability using this article https://www.atlassian.com/trust/security/report-a-vulnerability so Atlassian will provide an offical answer for that question.
We will continue to monitor the situation and provide a response soon.
Jodie
Please refer to our FAQ page, we should have a formal announcement soon:
https://confluence.atlassian.com/kb/faq-for-cve-2022-22963-cve-2022-22965-1115149136.html
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I would refer you to Atlassian Trust Center
and within they present security advisories advisories
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Jack,
Thank you.
But there are no updates about this "Spring2shell".
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Understand. But that is where the latest info is. You could raise a request with Atlassian Support.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thank you for the advisory page.
The page says that some of the server products DO use the impacted Spring version but are not vulnerable. I think it would be helpful if you could explain why they are not vulnerable. Is it because they don't use an affected JDK version or because they don't use Tomcat or something else?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I see Spring framework messages in the Fisheye startup logs, though it only supports JDK 8 so perhaps not an issue - apparently Spring is only vulnerable if used with Tomcat and JDK 9+.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.