We need to find out if our Jira/Conf would be vulnerable to either of these and if so what the steps are to fix.
These should be affecting Spring versions 5.0 to 5.0.4 and 4.3 to 4.3.14
https://pivotal.io/security/cve-2018-1270
https://pivotal.io/security/cve-2018-1271
Can you tell me how to find out what version of Spring Jira/Confluence run (or if they are even spring based at all!)
Thanks
Shah,
Our security team is aware of these issue and are currently investigating any potential impact to our products. As a per our security advisory publishing policy, if this issue has a critical severity impact with any of our products, we will send a security advisory alert.
We will send a copy of all posted security advisories to the 'Alerts' mailing list for the product concerned.
Note: To ensure you are on this list, please update your email preferences at https://my.atlassian.com/email.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.