Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

CVE-2024-47561 - Remediation

Sridhar R
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
January 24, 2025

 

 

 

 

Hi Team,

 

vulnerability

vulnerability.name

Affected File

CVE-2024-47561

Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code.
User

/home_9.12.10/atlassian-jira/WEB-INF/atlassian-bundled-plugins/analytics-client-8.2.17.jar -> META-INF/maven/org.apache.avro/avro

CVE-2024-47561

Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code.
User

/confluence/confluence/WEB-INF/atlassian-bundled-plugins/com.atlassian.analytics.analytics-client-8.3.5.jar -> META-INF/maven/org.apache.avro/avro

 

We have the above Critical vulnerability in our environment due to Jira and Wiki.

Can you please confirm if upgrading them to the below versions will resolve the issue?

 

Wiki upgrade from 8.5.17 to 8.5.18 

Jira Upgrade from 9.12.17 to 9.12.18

1 answer

1 vote
Aaron Pavez _ServiceRocket_
Community Champion
January 24, 2025

Hi @Sridhar R 

> Can you please confirm if upgrading them to the below versions will resolve the issue?

Jira and Confluence arent impacted by this. Check the Security bulletin:

https://confluence.atlassian.com/security/security-bulletin-november-19-2024-1456179091.html

And this:

https://www.atlassian.com/trust/data-protection/vulnerabilities

Only Bamboo Data Center and Server are impacted.

Regards

Suggest an answer

Log in or Sign up to answer