Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

What can we do if we are affected by the security vulnerability (CVE 2022 26135) but have not renewe

eperi July 13, 2022

Due to the security vulnerability, we were advised to download version 5 for Jira Service Desk (Service Management). However, since we have not renewed the contract or licenses, we would like to know if there is a way to install this version to comply with the security vulnerability?

Does Atlassian offer a solution for customers who do not want to move to the cloud and still use the application?

We are on version 4.9.0 for Jira Service Desk and Jira Software 8.20.2.

2 answers

0 votes
Florian Bonniec
Community Champion
July 13, 2022

You indeed need an active license to upgrade.

You can follow this mitigation solution

https://confluence.atlassian.com/kb/faq-for-cve-2022-26135-1142439167.html

 

You have to disable the system app Mobile Plugin for Jira. 

0 votes
Mayur Jadhav
Community Champion
July 13, 2022

Hi @eperi ,

I think you would need an active license to upgrade your application. If you are on 8.20.2 then you need to upgrade your Jira Software to 8.20.10.

I would suggest raising a ticket with Atlassian. If technical support is not available still you can raise sales or billing-related tickets and explain your scenario and ask for help if any.

 

 

Regards,
Mayur

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events