Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Next challenges

Recent achievements

  • Global
  • Personal

Recognition

  • Give kudos
  • Received
  • Given

Leaderboard

  • Global

Trophy case

Kudos (beta program)

Kudos logo

You've been invited into the Kudos (beta program) private group. Chat with others in the program, or give feedback to Atlassian.

View group

It's not the same without you

Join the community to find out what other Atlassian users are discussing, debating and creating.

Atlassian Community Hero Image Collage

Security Advisories for Jira family, September 2019

Atlassian announced two separate security advisories for Jira Server and Data Center products on September 18, 2019. This article is designed to help you determine which advisory may apply to you and how to ask for help here on Community.

 

The TLDR (too long, didn't read)

We recommend upgrading your Jira Server/Data Center instances to one of the following versions:

  • 7.6.16 or above in 7.6.x
  • 7.13.8 or above in 7.13.x
  • 8.1.3 or above in 8.1.x
  • 8.2.5 or above in 8.2.x
  • 8.3.4 or above in 8.3.x
  • 8.4.1 or above

 

Jira Server CVE-2019-15001

This includes Jira Software, Jira Core, and Jira Service Desk. Server and Data Center deployments are both included in the advisory.

Jira Cloud customers are not affected.

Please read the advisory for full details.

If you have questions specifically about CVE-2019-15001, please use this link to ask here on Community.

 

Jira Service Desk CVE-2019-14994

This applies to Jira Service Desk only. Server and Data Center deployments are both included in the advisory.

Jira Cloud customers are not affected. Jira instances that only have Core and/or Software are not affected by the advisory if Jira Service Desk is not installed.

Please read the advisory for full details.

If you have questions specifically about CVE-2019-14994 which affects Service Desk, please use this link to ask here on Community.

 

Mitigations

Unable to upgrade right away? Both CVEs can be mitigated with changes to your reverse proxy and/or Tomcat directly. See the specific KB articles for details on how to apply the mitigations:

Need help applying these mitigations? To keep questions manageable for the Community to answer, this article is locked for comments. You can ask a new question with this link, which includes the tags that help us see that the question relates to the advisories.

 

Migrations

Past security advisories have raised numerous questions around migrations. Some administrators, especially those with Server Starter (10 user) licenses, have opted to migrate to Atlassian Cloud instead of upgrading their existing Server instances to the latest versions. If this describes your situation, we are also happy to help with any migration questions using this link, which includes the tags that help us keep track of questions well.

0 comments

Comments for this post are closed

Community moderators have prevented the ability to post new comments.

TAGS

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you