3 ms·
Atlassian mentions in their original advisory[0] that Cloud is not vulnerable. But Atlassian usually just... leaves it at that. No clarification on if Cloud was
by dotty- 3y ago
Atlassian mentions in their original advisory[0] that Cloud is not vulnerable. But Atlassian usually just... leaves it at that. No clarification on if Cloud was ever vulnerable in the past or whether there was any evidence of exploitation attempts on Cloud customers. Something I wish they would provide more details on as my company is also an Atlassian customer.
[0]: https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html https://confluence.atlassian.com/security/cve-2023-22515-pri...
- sullivanmatt 3y agoIn all of these advisories there has never once been a mention of cloud being vulnerable. I think it's safe to assume cloud runs a similar, if not identical, codebase, and that these issues are simply patched there first before vulnerability announcements are published. But that's the type of thing no company is ever going to be willing to say in public.
- mschuster91 3y agoSomeone in here claimed recently that the Cloud products were forked many years ago, which sounds believable - there's tons of little stuff that only works on either Cloud or on-prem.