Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Security Advisory for JSM

Darlene Gariepy
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
October 20, 2021

We are current running Jira Software 8.19.1 Data Center with Jira Service Management 4.19.1.

With Insight 9.1.0 app installed. We are wanting to know if we are affected by the recent 

Jira Service Management Security Advisory 2021-10-20 ?

Thanks,

Brandon

2 answers

2 votes
Daniel Eads
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
October 20, 2021

Hi @Darlene Gariepy / Brandon,

You are affected by this advisory, as the version of Insight bundled with Jira Service Management Data Center is vulnerable until JSM Data Center is upgraded to 4.20.

If you cannot upgrade JSM Data Center right away, please follow the mitigation steps laid out in the advisory in order to work around the vulnerability as a temporary measure until you can work through an upgrade.

Cheers,
Daniel | Atlassian Community

1 vote
Robert Wen_Cprime_
Community Champion
October 20, 2021

You should be OK.  The versions of Insight under question are the ones before 8.9.3 according to the security bulletin.

https://confluence.atlassian.com/adminjiraserver/jira-service-management-security-advisory-2021-10-20-1085186548.html

Daniel Eads
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
October 20, 2021

For clarity, the 9.x versions indicate the Insight app is bundled with Jira Service Management Data Center (vs standalone/non-bundled versions such as 8.x), and don't relate to being before/after fixed versions in the advisory.

Like Robert Wen_Cprime_ likes this

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events