Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Lack of explicit "not affected"/"investigating" entries in Security Bulletins (e.g. CVE-2025-53506)

Aris Lambrianidis
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
August 20, 2025

Greetings,

Our vulnerability scanner has indicated that our Jira Data Center version is affected by CVE-2025-53506 (among other CVEs affecting Apache Tomcat 9.0.106).

This CVE has been confirmed to affect other Atlassian products leveraging Apache Tomcat.

As however there is no reference for Jira Data Center in the August 2025 Security Bulletin linked above, we are unsure whether the CVE affects us or not, as we know that Jira is also based on Apache Tomcat.

Given the above, I have one suggestion and one question:

1. It would be great if security bulletins positively indicated what the status of a CVE for a product is, even if there is no fix.

Such statuses could be:

  • "Not affected"
  • "Investigating"
  • etc.

2. Can anyone confirm whether any Jira Data Center versions are affected by  CVE-2025-53506?

1 comment

Comment

Log in or Sign up to comment
Ryan Goodwin
Contributor
August 20, 2025

Interesting that Confluence and Jira are not even listed in the August 19th bulletin... 

Like David Cowley likes this
TAGS
AUG Leaders

Atlassian Community Events