Atlassian announced two separate security advisories for Jira Server and Data Center products on September 18, 2019. This article is designed to help you determine which advisory may apply to you and how to ask for help here on Community.
The TLDR (too long, didn't read)
We recommend upgrading your Jira Server/Data Center instances to one of the following versions:
Jira Server CVE-2019-15001
This includes Jira Software, Jira Core, and Jira Service Desk. Server and Data Center deployments are both included in the advisory.
Jira Cloud customers are not affected.
If you have questions specifically about CVE-2019-15001, please use this link to ask here on Community.
Jira Service Desk CVE-2019-14994
This applies to Jira Service Desk only. Server and Data Center deployments are both included in the advisory.
Jira Cloud customers are not affected. Jira instances that only have Core and/or Software are not affected by the advisory if Jira Service Desk is not installed.
If you have questions specifically about CVE-2019-14994 which affects Service Desk, please use this link to ask here on Community.
Unable to upgrade right away? Both CVEs can be mitigated with changes to your reverse proxy and/or Tomcat directly. See the specific KB articles for details on how to apply the mitigations:
Need help applying these mitigations? To keep questions manageable for the Community to answer, this article is locked for comments. You can ask a new question with this link, which includes the tags that help us see that the question relates to the advisories.
Past security advisories have raised numerous questions around migrations. Some administrators, especially those with Server Starter (10 user) licenses, have opted to migrate to Atlassian Cloud instead of upgrading their existing Server instances to the latest versions. If this describes your situation, we are also happy to help with any migration questions using this link, which includes the tags that help us keep track of questions well.
Community moderators have prevented the ability to post new comments.
Daniel EadsAtlassian Team
Connect with like-minded Atlassian users at free events near you!Find an event
Connect with like-minded Atlassian users at free events near you!
Unfortunately there are no Community Events near you at the moment.Host an event
You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events