Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

How to fix Multiple Products Security Advisory - CVE-2022-26136, CVE-2022-26137

Han, Wanlin (Denny)
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
July 21, 2022

currently, we running following products, How can we fix those two Vulnerabilities?

We are currently running:

Bamboo -  8.0.4

Bitbucket - 7.17.5

Confluence - 7.13.7

Crowd - 4.4.0

Jira - 8.20.10

Jira Service Management - 4.20.10

I am new for those products, could you give me the steps to fix,  Thanks

2 answers

1 vote
Sebastian Krzewiński
Community Champion
July 21, 2022

Hi @Han, Wanlin (Denny) 

 

Everything about both CVE's you can find here - https://confluence.atlassian.com/security/multiple-products-security-advisory-cve-2022-26136-cve-2022-26137-1141493031.html

 

You need to upgrade your apps to versions mentioned in above document. How to upgrade? Every app has docs about that. Search on confluence.atlassian.com.

 

Regards,

Seba

Alin Faur
Contributor
July 22, 2022

Is there any chance for identifying a workaround that would only patch applications in their existing version instead of having to upgrade?

Sebastian Krzewiński
Community Champion
August 1, 2022

Hi

 

If there is nothing about workaround I'm afraid that upgrade is the only way to fix it.

You can also talk with network/security engineers to block access to your instances from the Internet or you can talk with them about some solution that will prevent you any security issues (e.g. WAF for Azure or something similar).

 

Regards,

Seba

Like Alin Faur likes this
0 votes
Sam Earnshaw
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
August 8, 2022

Your Confluence instance is not vulnerable, but I am in the same boat as you with the other systems. As there are no workarounds, I am planning to upgrade them ASAP and I would suggest you do the same.

Suggest an answer

Log in or Sign up to answer