Did anybody else get this email from Atlassian:
yet whne I go to the Atlassian security center (https://www.atlassian.com/trust/security/advisories) nothing for this month:
As an IT professional concerned with Security and knowing that spoofed email with links or attachments are how most companied get hacked. I always prefer to check the from known good URLs that did not come from email. the above URL I used was supplied by Atlassian support when I opened a ticket the last time I got email from them and their links in the email looked suspicious.
Hi @Rhyrus Falcone - the email is legitimate (edit: I should clarify that I can't be 100% certain whether the email you got is legitimate without seeing it, but I can confirm Atlassian sent out an email today notifying customers of a security advisory in Jira and Jira Service Management). It links to the following security advisory which is hosted on the atlassian.com domain:
https://confluence.atlassian.com/jira/jira-security-advisory-2022-04-20-1115127899.html
The vulnerability is also tracked in the following issues on jira.atlassian.com which also link to the advisory above:
https://jira.atlassian.com/browse/JRASERVER-73650
https://jira.atlassian.com/browse/JSDSERVER-11224
Our advisories page will be updated later today.
@Brian Adeloye If we are on an LTS, we have to get off that to consume a fix then?
@Brian Adeloye Since the only thing is the bundled MobileApp that is effected. I can just disable that app for now and not worry about Jira since non of my other apps are listed in https://confluence.atlassian.com/jira/jira-security-advisory-2022-04-20-1115127899.html, right?
I have a major deployment coming up at the end of May 2022 and can't take three days to prep and upgrade my three environments right now (dev, test, and prod).
@Joey Klein there are bug fixes available for LTS releases, too. More information can be found in https://confluence.atlassian.com/jira/jira-security-advisory-2022-04-20-1115127899.html
It looks like you're new here. Sign in or register to get started.