Skip to end of metadata
Go to start of metadata

A critical security vulnerability (CVE-2022-42889) was discovered in the Apache Commons Text including version 1.5 up to 1.9 on 13 November 2022.

Impact on Atlassian Products

There is an official statement from Atlassian for Confluence.

 Confluence IS NOT VULNERABLE to CVE-2022-42889.

This bug was created to track the change required to upgrade the Apache Commons Text library and can be used by customers to follow its progress and get notified on the next numbered release.

Confluence does not use the vulnerable module org.apache.commons.text.StringSubstitutor


The same is true for Jira:

Impact on Seibert Media Products

Regarding the official statement from Apache, we made sure our apps do not use the affected Commons class and be therefore not vulnerable for CVE-2022-42889. 

Seibert Media apps from Atlassian's Marketplace including all joint venture apps

Data Center and Server Apps

  • Not affected. No action is required.

Cloud Apps

  • Not affected. No action is required.
Linchpin Hey

Not affected. No action is required.

Shortlink for this page:

  • No labels
This page was last edited on 11/24/2022.