K15t Apps and Text4Shell (CVE-2022-42889)
Background
On Thursday, , a Remote Code Execution vulnerability in the popular Apache Commons Text library was published as CVE-2022-42889 (and is sometimes referred to as Text4Shell).
We became aware of this vulnerability and have assessed all K15t and K15t Labs marketplace apps.
As a result of this assessment, we have not found any of our apps to be affected by this vulnerability. None of our apps uses the vulnerable component in a way that transfers user-controlled input into the component.
As of now Atlassian hasn't published a security advisory for Confluence or Jira.
K15t apps are not affected by CVE-2022-42889
None of our Cloud, Server or Data Center apps are affected by CVE-2022-42889 as they either do not use the library or do not use the vulnerable component in a vulnerable way.
Additionally we have taken actions to keep the apps secure in the future and either updated the library or removed it from the apps.
- Backbone Issue Sync
- Inline Comments in the Editor
- Scroll Documents
- Variants for Scroll Documents
- Translations for Scroll Documents
- Scroll Exporters
- Scroll PDF Exporter
- Scroll Word Exporter
- Scroll HTML Exporter
- Comala Document Mgmt for Scroll Exporter
- Scroll CHM Exporter
- Scroll DocBook Exporter
- Scroll EclipseHelp Exporter
- Scroll EPUB Exporter
- Scroll ImageMap
- Scroll Remote Publishing Endpoint
- Scroll Translations
- Scroll Viewport
- Scroll Versions
- Comala Document Mgmt for Scroll Versions
- Backbone Issue Sync
- Scroll Content Quality for Confluence
- Scroll Documents
- Variants for Scroll Documents
- Translations for Scroll Documents
- Scroll Exporters
- Scroll Exporter Extensions
- Scroll PDF Exporter
- Scroll Word Exporter
- Scroll HTML Exporter
- Scroll ImageMap
- Scroll Viewport
- Orderly Databases
- Expando for Confluence
- Counters for Confluence
- Inspector Sketch for Jira
- Inspektor Sketch for Confluence
- Scroll WP Publisher
- Create from Template Pro
- Proofreading for Confluence
- Page Links for Confluence
- Storage Format Editor for Confluence
- Meeting Icebreakers for Confluence
We are here to support you
If you have additional questions, please do not hesitate to reach out to us at help@k15t.com.