The notification of the Broken Authentication vulnerability went out saying the following versions 5.3.0 to 5.3.1 and 5.4.0 to 5.5.0 are affected by this vulnerability.
Are older versions affected? We're still on 4.22.6
Hi @Roman Treynker
Welcome to the Atlassian Community! As specified in the Security Advisory, no Jira Service Management (JSM) 4.x.x versions are affected by the vulnerability. For all affected 5.x.x versions, new bugfix releases have been published.
A slight correction to @Tommy Augustine's comment: JSM 4.22.x will reach its End of Life date on February 16, 2024 – right around the same time as the Jira Server end of support.
Cheers,Ben
I'm going to say "No" it's not. My logic for this answer is that 4.22 is not yet End Of Life for another year (February 16, 2024), and because it is not EOL yet, Atlassian would still report the version as affected in their open ticket
Edit: Corrected EOL Date (Thanks Ben!)
Thanks, Ben! That's a less stressful answer to an admin now lol
Thank you, both!
It looks like you're new here. Sign in or register to get started.