Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

CVE-2018-1270 or CVE-2018-1271 - any version of Jira/Confluence vulnerable to these?

SA April 10, 2018

We need to find out if our Jira/Conf would be vulnerable to either of these and if so what the steps are to fix. 

These should be affecting Spring versions 5.0 to 5.0.4 and 4.3 to 4.3.14

https://pivotal.io/security/cve-2018-1270

https://pivotal.io/security/cve-2018-1271

 

Can you tell me how to find out what version of Spring Jira/Confluence run (or if they are even spring based at all!)

 

Thanks

 

1 answer

1 accepted

1 vote
Answer accepted
joshloe
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
April 10, 2018

Shah,

Our security team is aware of these issue and are currently investigating any potential impact to our products. As a per our security advisory publishing policy, if this issue has a critical severity impact with any of our products, we will send a security advisory alert.

We will send a copy of all posted security advisories to the 'Alerts' mailing list for the product concerned.

Note: To ensure you are on this list, please update your email preferences at https://my.atlassian.com/email.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events