The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Heartbleed on Jira 5.2

Lynn Lynn
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
April 20, 2014

Would like to check whether does the Heartbleed affect Jira 5.2? Any documents to state whether if affect or not as i need to report to my IT side?It affects, what will be the remedy steps to fix it? If i need to check the OpenSSL version installed on Jira, what would be the steps to check? thks

2 answers

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

0 votes
yen_mrkid
April 20, 2014
just upgrade it or you  can alternatively recompile OpenSSL with -DOPENSSL_NO_HEARTBEATS.
 
0 votes
Pedro Souza
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
April 20, 2014

Hi,

The Heartbleed has been confirmed, after investigations, to be an infrastructure issue. Our findings have been published to this blog that outlines the issue context, please take some time to review the details here: http://blogs.atlassian.com/2014/04/openssl-cve-2014-0160-atlassian/

To find out whether you are affected or not, please check the version of OpenSSL that is running on your server. OpenSSL 1.0.1 or 1.0.2 releases may be affected. The entirety of OpenSSLs statement regarding this matter can be accessed after this link: https://www.openssl.org/news/secadv_20140407.txt.

If you have followed our instructions on configuring SSL in any product (for example, https://confluence.atlassian.com/display/STASH/Securing+Stash+with+Tomcat+using+SSL), you are not using Tomcat’s APR and “native” OpenSSL libraries, but Java’s own implementation in javax.net.ssl.

Java SSL does not even support hearbeats.

If you scroll down that page, you will see that the config for APR OpenSSL is different. It includes directives such as SSLCertificateFile and SSLCertificateKeyFile.

If you have installed a WAR distribution, then we are not handling SSL and the app container might be using host’s libraries. ****Again, if you configured the server not to use APR, you’re fine***

Cheers,

Pedro Souza.

TAGS
AUG Leaders

Atlassian Community Events