The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Is Jira Software Data Center (on-prem) vulnerable to CVE-2019-17571 ?

jy
February 20, 2022

Based on https://confluence.atlassian.com/kb/faq-for-cve-2021-44228-1103069406.html

The following products use the Atlassian-maintained fork of Log4j 1.2.17:

Jira Software and Data Center

 

How does it mitigate and resolve against this critical vulnerability which affect log4j1.2.17?

 

https://nvd.nist.gov/vuln/detail/CVE-2019-17571

 

Does Atlassian not intend to upgrade their log4j to 2.17.0 or 2.17.1?

 

 

1 comment

Comments for this post are closed

Community moderators have prevented the ability to post new comments.

Fabio Racobaldo _Catworkx_
Community Champion
February 21, 2022

Hi @jy ,

in order to mitigate that security issue you should disable JMSAppender as specified in the linked article.

Btw, Atlassian says that they forked log4j 1.2.17 (in 1.2.17-atlassian-3) in order to delete the code affected. Therefore, JIRA is not vulnerable to CVE-2019-17571.

Please take a look to the following issue https://jira.atlassian.com/browse/JRASERVER-62838

Hope this helps,

Fabio

TAGS
AUG Leaders

Atlassian Community Events