Security Advisories for Jira family, September 2019

Atlassian announced two separate security advisories for Jira Server and Data Center products on September 18, 2019. This article is designed to help you determine which advisory may apply to you and how to ask for help here on Community.

 

The TLDR (too long, didn't read)

We recommend upgrading your Jira Server/Data Center instances to one of the following versions:

  • 7.6.16 or above in 7.6.x
  • 7.13.8 or above in 7.13.x
  • 8.1.3 or above in 8.1.x
  • 8.2.5 or above in 8.2.x
  • 8.3.4 or above in 8.3.x
  • 8.4.1 or above

 

Jira Server CVE-2019-15001

This includes Jira Software, Jira Core, and Jira Service Desk. Server and Data Center deployments are both included in the advisory.

Jira Cloud customers are not affected.

Please read the advisory for full details.

If you have questions specifically about CVE-2019-15001, please use this link to ask here on Community.

 

Jira Service Desk CVE-2019-14994

This applies to Jira Service Desk only. Server and Data Center deployments are both included in the advisory.

Jira Cloud customers are not affected. Jira instances that only have Core and/or Software are not affected by the advisory if Jira Service Desk is not installed.

Please read the advisory for full details.

If you have questions specifically about CVE-2019-14994 which affects Service Desk, please use this link to ask here on Community.

 

Mitigations

Unable to upgrade right away? Both CVEs can be mitigated with changes to your reverse proxy and/or Tomcat directly. See the specific KB articles for details on how to apply the mitigations:

Need help applying these mitigations? To keep questions manageable for the Community to answer, this article is locked for comments. You can ask a new question with this link, which includes the tags that help us see that the question relates to the advisories.

 

Migrations

Past security advisories have raised numerous questions around migrations. Some administrators, especially those with Server Starter (10 user) licenses, have opted to migrate to Atlassian Cloud instead of upgrading their existing Server instances to the latest versions. If this describes your situation, we are also happy to help with any migration questions using this link, which includes the tags that help us keep track of questions well.

0 comments

Comments for this post are closed

Community moderators have prevented the ability to post new comments.

TAGS
AUG Leaders

Atlassian Community Events