Hi Daniel,
Will this risk affect JIRA and confluence?
Jira and Confluence are not affected at all by this CVE. Cheers!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Daniel,
Thank you for your reply. Jira and confluence are installed on our server. Can we fix this risk item? Are there any links to fixes? thank you
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
There is no risk item for Jira and Confluence. The CVE only affects Fisheye and Crucible, which are not part of Jira or Confluence.
If you do not have Fisheye or Crucible installed (these are separate applications entirely), you do not need to take any action.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hey there,
According to our issue tracker, Atlassian Fisheye and Atlassian Crucible contained vulnerable versions of the Apache Commons FileUpload library noted in CVE-2016-1000031. However, our implementation of these libraries did not use the DiskFileItem class which was the attack vector in this advisory. Despite that, Fisheye and Crucible 4.7.0 now contain a patched version of the library.
Cheers,
Daniel
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.