4 ms·
The irritating thing about this is that Atlassian initially sent out an email on August 25th stating it only affected servers where a certain setting was enable
by thatsamonad 5y ago
The irritating thing about this is that Atlassian initially sent out an email on August 25th stating it only affected servers where a certain setting was enabled that allowed users to self-register. They then updated the CVE wording to state it affected all instances on the affected versions even with that setting disabled, but didn’t send out a follow up email to customers until yesterday (September 3rd - right before a US holiday weekend!) at around 4pm PDT. Customers who thought they could delay upgrading for a bit and weren’t monitoring the ticket for the CVE directly likely went on with their business for over a week being vulnerable to the exploit.