URL Path Traversal in Jira Service Desk Server and Jira Service Desk Data Center

Irnik Iv
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
October 23, 2019

The issue:

https://jira.atlassian.com/browse/JSDSERVER-6517

 

My current product version:

JIRA v7.8.0

JIRA Agile v7.8.0-DAILY20180212023044

I don't have installed Jira Service Desk Server and Jira Service Desk Data Center.

 

Should I worry about this vulnerability issue? Is it affecting my products?

2 answers

2 accepted

1 vote
Answer accepted
Alexis Robert
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
October 23, 2019

Hi @Irnik Iv , 

 

you are not affected by this security issue, but since your instance version is 7.8.0 you're still vulnerable to many securiy issues : https://confluence.atlassian.com/jira/security-advisories-112853939.html

You should upgrade as soon as possible to Jira 7.13.8.

 

Let me know if this helps, 

 

--Alexis 

Boris MBOUMEHANG
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
October 23, 2019

Well seen Alexis! ;) 

Like Alexis Robert likes this
0 votes
Answer accepted
Boris MBOUMEHANG
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
October 23, 2019

Hi, 

First of all, welcome to that Atlassian Community. It is good to have you here. 

As mentionned in the CVE details, this vulnerability only affects Jira Service Desk (Server and Data Center), even if users who set the "Browse Project" permission for their Jira Software or Jira Core projects to "Group - Anyone". 
So, you do not have to worry. 

But, if you still have doubts, you can ask the Atlassian support for confirmation.

I hope this will help. 

Thanks
Boris

Suggest an answer

Log in or Sign up to answer