Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Apache Struts vulnerability CVE-2020-17530

재웅 최 December 9, 2020

I have Apache Struts2 vulnerability CVE-2020-17530, is Jira 7.13.18 unaffected?

2 answers

2 accepted

1 vote
Answer accepted
Chris Hardie January 25, 2021

I previously posed the question to support and the response I received:

"As described in this old Jira bug JRASERVER-66491 (not directly related to CVE-2020-17530, but it contains the information about Struts.), Atlassian Jira does not use Apache Struts 2.

Therefore, we can confirm that vulnerability CVE-2020-17530 does not affect Jira 8.5.5."

0 votes
Answer accepted
Iago Docando
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
December 11, 2020

All I can tell you is that

https://www.cvedetails.com/vulnerability-list/vendor_id-3578/product_id-8170/Atlassian-Jira.html

doesn't include that vulnerability at all in the list. There's nothing there from 2020 though.

Maybe someone more security-savy can tell you more but regardless this seems a great question to ask directly to Atlassian rather than to the community. Who better than them to give you a official answer as oposed to an opinion? https://support.atlassian.com/contact/#/

Suggest an answer

Log in or Sign up to answer