Missed Team ’24? Catch up on announcements here.

×
Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Does CVE-2018-10054 still apply to affected JSM installations that DO NOT have Insight installed?

Deleted user October 21, 2021

Does CVE-2018-10054 still apply to affected JSM installations that DO NOT have Insight installed?

1 answer

3 votes
Dave Theodore [Coyote Creek Consulting]
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
October 22, 2021

This vuln actually affects the H2 database that ships with Jira. Affected versions of Insight allow it to be exploited, but it's best to assume that there could be other attack vectors as well.  My recommendation would be to follow the Mitigation steps in the announcement even if you don't intend to use Insight. Of course, this means you need to use a production grade database and migrate off of H2.  H2 serves no useful purpose if you are using a supported database, so you should remove it.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events