Please suggest us to which version we have to Upgrade Jira to Latest Version. Based on given Vulnerabilities or give me any other solution to resolve these Vulnerabilities.
Jira:
Current Jira Version: v8.20.10
Server version: Apache/2.4.37 (Red Hat Enterprise Linux)
Apache Tomcat/8.5.78
Below are the Vulnerabilities:
- Vulnerable Server Version (Apache RHEL 2.4.37) was running on multiple hosts.-> It was observed that the multiple hosts (13.234.49.120 & 3.6.35.140) were running Apache HTTP Server version 2.4.37 which is outdated and vulnerable. Apache version needs to be upgraded to the latest and supported version ( Latest version- 2.4.54)
- Multiple hosts were running vulnerable versions of jQuery-> It was observed that remote host (13.234.29.120) was running vulnerable jQuery UI version 2.24 which is vulnerable to to various vulnerabilities. Please upgrade to latest and jQuery version.
- Multiple hosts are vulnerable to Lucky13 vulnerability- It was observed that the Host (3.6.35.140 ) is vulnerable to Lucky13 vulnerability and to remediate the vulnerability, we should remove the CBC ciphers and use only AES-GCM Ciphers.