Hello,
I would like to inquire whether the files related to Apache Commons Text: CVE-2022-42889 can be safely deleted, considering that they are not being utilized by the application itself?
Kindly,
Marios.
Hello @mbitzis
It looks like this is a bug they are actively working. From looking at some of the comments it looks like it has been fixed in version 9.6 so upgrading might be the way to go.
Disclaimer: Jira IS NOT vulnerable to CVE-2022-42889. Jira does not use the vulnerable module org.apache.commons.text.StringSubstitutor
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.