Action required: Atlassian Connect vulnerability allows bypass of app qsh verification via context JWTs

@AndyJames the issues you’re seeing are unrelated to these changes. ACSB v2.1.9 has recently been published to remove the requirement that baseURL is unique, rather than apps using the client key as described in Ensuring your Atlassian Connect app handles customer site imports. This uniqueness check in ACSB was sometimes causing issues with installations and re-imports. Please let us know if you still encounter issues with ACSB v2.1.9.

1 Like