Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

CVE-2022-0540

Kiran Mannava
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
April 20, 2022

Does  Jira standalone installation type is affected by  CVE-2022-0540 ?

 

Thanks

2 answers

1 vote
Robert Wen_Cprime_
Community Champion
April 20, 2022

Hello, @Kiran Mannava ! Welcome to the Atlassian Community!

Yes, the vulnerability does affect Jira Server.

Tony Tovar - ZOLL
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
April 20, 2022

How would we know if this had been exploited? Is there an 'indicator of compromise' (IoC) we should look for in the logs?

Robert Wen_Cprime_
Community Champion
April 20, 2022

From what I've read (and Atlassian's notice is here), there don't appear to be any reports of known exploits.

0 votes
inet.s
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
April 21, 2022

Is Jira 8.12 is affected? we do not understand right:

 

  • All versions before 8.13.18
  • 8.14.x
  • 8.15.x
  • 8.16.x
  • 8.17.x
  • 8.18.x
  • 8.19.x
  • 8.20.x before 8.20.6
  • 8.21.x

8.12 is not EOL, but seems there is no upgrade to download.

8.12 (EOL date: 26 August, 2022)

Thanks.

Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
April 21, 2022

Yes. 8.12.x versions are affected by this advisory, as this version was released before 8.13.18.  Although 8.12 is not at EOL yet, not all bug fixes will be ported back to these prior versions in all cases. 

8.13.x and 8.20.x are the current Long Term Support releases where we will expect to see a backport of security fixes such as in this case.

Like # people like this

Suggest an answer

Log in or Sign up to answer