Mitigation solution for CVE-2022-26135

Yashwanth Jakkula June 29, 2022

Need Mitigation solution for the issue CVE-2022-26135.

Please let me know for any possible solution.

 

1 answer

1 vote
Sreenivasaraju P
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
June 29, 2022

Hi @Yashwanth Jakkula ,

Atlassian provided mitigation details, please refer.

Mitigation

Installing a fixed version of Jira or Jira Service Management is the surest way to remediate CVE-2022-26135. If you are unable to immediately upgrade Jira or Jira Service Management, then as a temporary workaround, you can manually upgrade Mobile Plugin for Jira Data Center and Server (com.atlassian.jira.mobile.jira-mobile-rest) to the versions specified in this section (or disable the plugin).

The following versions of the Mobile Plugin for Jira app contain a fix for this issue:

  • 3.1.5 (only compatible with Jira 8.13.x and JSM 4.13.x)
  • 3.2.15 (only compatible with Jira 8.20.x - 8.22.x, only compatible with JSM 4.20.x - 4.22.x)

 

For more details.

https://confluence.atlassian.com/jira/jira-server-security-advisory-29nd-june-2022-1142430667.html

Suggest an answer

Log in or Sign up to answer