Jaspersoft CVE-2022-22978 and Clarity
search cancel

Jaspersoft CVE-2022-22978 and Clarity

book

Article ID: 280813

calendar_today

Updated On:

Products

Clarity PPM On Premise Clarity PPM SaaS

Issue/Introduction

Is Clarity embedded Jaspersoft solution vulnerable to CVE-2022-22978?

Environment

All Clarity supported versions, with Jaspersoft 7.8 or 8.1.1

Resolution

This solution is not vulnerable.

In respect to Clarity, Jaspersoft is an embedded software. Clarity does not use Jaspersoft native authentication, which can expose this vulnerability as described in CVE-2022-22978. Clarity does not use Spring-based authentication as documented in KB 248233 - CVE-2022-22950 Spring framework vulnerability - Clarity PPM.

Clarity has a custom authentication solution where Clarity communicate with Jaspersoft by sending an encrypted token (which are encrypted using tenant-level key stores) and Clarity's custom plugin in Jaspersoft can only decrypt the token and either pass or fail the authentication. Also, all the users that are synced to Jaspersoft from Clarity do not have passwords persisted in Jaspersoft DB.

Additional Information