Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Log4j vulnernerability in jira apps

Ramakrishna Grandhi
Contributor
December 13, 2021

Hi, we've a jira server app and its .jar file. It has a dependency on log4j 1.2.6 indirectly i.e. we dont have the ref in pom.xml but one of the dependencies has it. Can someone advise on how to make this transitive dependency to latest log4j?

1 answer

1 accepted

1 vote
Answer accepted
Rahul Aich [Nagra]
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
April 22, 2015

Check what is defined in the browse-projects permission. Do you have any project role or group defined in it.

If yes, check if the user is part of that role or group.

Only way a user can get access to a project is by having the browse issue permission.

Why he is not able to view issues is a different issue and reasons can be many,buts thats not the issue here.

Rahul

Andrej V.
April 22, 2015

Thanks.

I checked what is defined in the browse-projects permission.

We have an permission that allows browse projects by "Author".

So Any user that can create an issues can see any project no metter what permissions are set in project for group or role or user.

 

Suggest an answer

Log in or Sign up to answer