Upgrading Jira Software 8.13.5 & Jira Service Mgt 4.13.7 Vulnerability CVE-2022-26135

Shita Dewi June 30, 2022

Hi All,

We're currently using Jira Software v8.13.5 & Jira Service Mgt v4.13.7, related to current  vulnerability finding CVE-2022-26135 where we have to upgrade Jira versions we seek advise on :

  1. Which Jira version is best to upgrade to if we need quick fixing?
  2. What are the risk we need to take note in regards to upgrading the versions for both Jira Software & Service Mgt?

Thanks!

1 answer

0 votes
Sreenivasaraju P
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
June 30, 2022

Hi @Shita Dewi ,

Please refer fix version section of security advisory

 

Fixed Versions

Jira Core Server, Jira Software Server, and Jira Software Data Center:

  • 8.13.x >= 8.13.22
  • 8.20.x >= 8.20.10
  • 8.22.x >= 8.22.4
  • 9.0.0

Jira Service Management Server and Data Center:

  • 4.13.x >= 4.13.22
  • 4.20.x >= 4.20.10
  • 4.22.x >= 4.22.4
  • 5.0.0

more details @

https://confluence.atlassian.com/jira/jira-server-security-advisory-29nd-june-2022-1142430667.html

Shita Dewi June 30, 2022

Hi, 

Thanks for the quick response.

We are planning to upgrade to either one of the version, however we need to know which is the best and simplest version to upgrade to, considering to upgrade the current version from 8.13.x to 8.20.x or 8.22.x would be skipping some versions.

We need to know each comparisons based on the risks and upgrading process (which is simpler).

 

Regards,

 

Shita

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
VERSION
8.13.5
TAGS
AUG Leaders

Atlassian Community Events