You're on your way to the next level! Join the Kudos program to earn points and save your progress.
Level 1: Seed
25 / 150 points
Next: Root
1 badge earned
Challenges come and go, but your rewards stay with you. Do more to earn more!
What goes around comes around! Share the love by gifting kudos to your peers.
Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!
Join now to unlock these features and more
The Atlassian Community can help you and your team get more value out of Atlassian products and practices.
Atlassian announced two separate security advisories for Jira Server and Data Center products on September 18, 2019. This article is designed to help you determine which advisory may apply to you and how to ask for help here on Community.
The TLDR (too long, didn't read)
We recommend upgrading your Jira Server/Data Center instances to one of the following versions:
Jira Server CVE-2019-15001
This includes Jira Software, Jira Core, and Jira Service Desk. Server and Data Center deployments are both included in the advisory.
Jira Cloud customers are not affected.
Please read the advisory for full details.
If you have questions specifically about CVE-2019-15001, please use this link to ask here on Community.
Jira Service Desk CVE-2019-14994
This applies to Jira Service Desk only. Server and Data Center deployments are both included in the advisory.
Jira Cloud customers are not affected. Jira instances that only have Core and/or Software are not affected by the advisory if Jira Service Desk is not installed.
Please read the advisory for full details.
If you have questions specifically about CVE-2019-14994 which affects Service Desk, please use this link to ask here on Community.
Mitigations
Unable to upgrade right away? Both CVEs can be mitigated with changes to your reverse proxy and/or Tomcat directly. See the specific KB articles for details on how to apply the mitigations:
Need help applying these mitigations? To keep questions manageable for the Community to answer, this article is locked for comments. You can ask a new question with this link, which includes the tags that help us see that the question relates to the advisories.
Migrations
Past security advisories have raised numerous questions around migrations. Some administrators, especially those with Server Starter (10 user) licenses, have opted to migrate to Atlassian Cloud instead of upgrading their existing Server instances to the latest versions. If this describes your situation, we are also happy to help with any migration questions using this link, which includes the tags that help us keep track of questions well.
Daniel Eads
Atlassian TeamSolutions Engineer
Atlassian
Austin
607 accepted answers
0 comments