Hi ,
We are using a vunelrable jira server edition.8.19.X for CVE-2022-26135 - Full-Read Server Side Request Forgery in Mobile Plugin for Jira Data Center and Server.But the mobile plugin for jira is disabled .Are we still affected and if affected is the it still a serious severity.
Hello @suresh kumar ,
Thanks for reaching out, and Yes you can disable the app to mitigate the threat until you are able to update covered in the FAQ for CVE-2022-26135 for disabling the app noting:
Disable the app The Mobile Plugin for Jira app is in a special category of System Apps such that it can be disabled similarly to User-installed apps. Use the "Disable" button on the app to mitigate the vulnerability until you can upgrade Jira.
The Mobile Plugin for Jira app is in a special category of System Apps such that it can be disabled similarly to User-installed apps. Use the "Disable" button on the app to mitigate the vulnerability until you can upgrade Jira.
However, we do recommend updating the app regardless at your earliest convenience to make sure that the threat is removed from the system to prevent accidental re-activation.
Regards,Earl
It looks like you're new here. Sign in or register to get started.