Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

CVE-2022-26135 - Mobile Plugin for Jira - Are we affected if the plugin is disabled

suresh kumar
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
June 29, 2022

Hi , 

We are using a vunelrable jira server edition.
8.19.X for 
CVE-2022-26135 - Full-Read Server Side Request Forgery in Mobile Plugin for Jira Data Center and Server.

But the mobile plugin for jira is disabled .

Are we still affected and if affected is the it still a serious severity.

1 answer

2 votes
Earl McCutcheon
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
June 29, 2022

Hello @suresh kumar ,

Thanks for reaching out, and Yes you can disable the app to mitigate the threat until you are able to update covered in the FAQ for CVE-2022-26135  for disabling the app noting:

Disable the app

The Mobile Plugin for Jira app is in a special category of System Apps such that it can be disabled similarly to User-installed apps. Use the "Disable" button on the app to mitigate the vulnerability until you can upgrade Jira.

However, we do recommend updating the app regardless at your earliest convenience to make sure that the threat is removed from the system to prevent accidental re-activation.

Regards,
Earl

Suggest an answer

Log in or Sign up to answer