We need to find out if our Jira/Conf would be vulnerable to either of these and if so what the steps are to fix.
These should be affecting Spring versions 5.0 to 5.0.4 and 4.3 to 4.3.14
https://pivotal.io/security/cve-2018-1270
https://pivotal.io/security/cve-2018-1271
Can you tell me how to find out what version of Spring Jira/Confluence run (or if they are even spring based at all!)
Thanks
Shah,
Our security team is aware of these issue and are currently investigating any potential impact to our products. As a per our security advisory publishing policy, if this issue has a critical severity impact with any of our products, we will send a security advisory alert.
We will send a copy of all posted security advisories to the 'Alerts' mailing list for the product concerned.
Note: To ensure you are on this list, please update your email preferences at https://my.atlassian.com/email.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.