Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Next challenges

Recent achievements

Recognition

  • Give kudos
  • My kudos

Leaderboard

  • Global

Trophy case

Kudos (beta program)

Kudos logo

You've been invited into the Kudos (beta program) private group. Chat with others in the program, or give feedback to Atlassian.

View group

It's not the same without you

Join the community to find out what other Atlassian users are discussing, debating and creating.

Atlassian Community Hero Image Collage

Jira Service Desk Security Advisory 2019-11-06 Workaround

The following security advisory was received informing us of a bypass that can allow attackers the ability to view all issues through any project within a Jira instance:

https://confluence.atlassian.com/jira/jira-service-desk-security-advisory-2019-11-06-979412717.html?utm_source=alert-email&utm_medium=email&utm_campaign=Jira%20Service%20Desk%20Server%20and%20Data%20Center-advisory_november-2019_EML-5814&jobid=104383358&subid=1333322718

One of the workarounds provided (Workaround 2) references a LocationMatch configuration that is very similar to a configuration to a .conf file through a prior security advisory (https://confluence.atlassian.com/jira/jira-service-desk-security-advisory-2019-09-18-976171274.html?utm_source=alert-email&utm_medium=email&utm_campaign=Jira%20Service%20Desk%20Server%20and%20Data%20Center-advisory_september-2019_EML-5414&jobid=104302939&subid=1333322718).

Will the application of the LocationMatch configuration as stated below cover Jira projects as well as Service Desk projects:

<LocationMatch "/(.*\.\.)">
   Order Allow,Deny
    Deny from  all
</LocationMatch>

The workaround provided for the recent security advisory is as follows:

<LocationMatch "/servicedesk/.*\.jsp.*">
   Order Allow,Deny
    Deny from  all
</LocationMatch>

Please advise. 

0 answers

Suggest an answer

Log in or Sign up to answer
TAGS
Community showcase
Asked in Jira Service Desk

Calling all Insight users, we need your help!

Hello Insight users,  As part of our (Mindville's) acquisition by Atlassian, our training team is looking to build some new Insight training materials. It would really helpful if you can ...

183 views 2 3
View question

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you