Hello,
I am using the version 3.12.2 of Jira service desk. I received a mail from Atlassian which inform that a critical security vulnerability exists in Jira Service Desk Server and Data Center for this version. In the link to be followed it is said that an upgrade to the version 3.16.8 fixes the issue.
Is the upgrade the only way to fix the issue?
If yes, can you please give the details of how to proceed with the upgrade?
Thank you in advance,
Best regards,
Bruno.
Hi Bruno,
There is a short-term alternative to upgrading. In the long run, I would recommend an upgrade but short-term you can employ the mitigation described in the security advisory. This involves blocking a particular path at your reverse proxy (if you have one set up) or modifying the Tomcat configuration used to serve Jira. It's worth noting that you'll also want to follow similar steps for the other Jira Server advisory from Wednesday - steps for mitigation on that one are here.
Given the effort it takes to mitigate both, you may find an upgrade simpler. We've got a detailed article with upgrade steps at this link.
Cheers,
Daniel
Thank you for the information Daniel. Two additional questions:
1. Can you confirm that the upgrade won't have any impact on the license we purchased for the version 3.12.2 of Jira service desk?
2. Will that upgrade have any impact on the queries / filters that we created on the actual version (3.12.2)? Is there any other impact / difficulties you predict we may face with that upgrade?
Best regards,
Bruno.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Bruno,
Cheers,
Daniel
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thank you for the answers Daniel. We will proceed with the upgrade. We will inform you in case we need help.
Best regards,
Bruno.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hello Daniel,
The upgrade has been done and it was a success.
Thank you for your help.
Best regards,
Bruno.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.