Dear Sirs
My customer has a Jira Server 7.2.2 installation. The log4j library version installed in is 1.2.16. Associated with this version there was two vulnerabilities CVE-2019-17571 and CVE-2020-9488.
Is there any type of affection on Jira with both vulnerabilities?
If so, could you provide me with the workarround to fix them?
Thank you very much!
Best regards
I don't think the Answer has anyting to do with the vulnerabilities fvillena asked about.
I checked the exact Version of Log4j wich was used in our Version of Confluence & jira. In our case, it was 1.2.17-atlassian-3 wich is the atlassian Branch, wich was the fix for CVE-2019-17571. I will have to go and check the 2020 one, but you will proberbly find the answer with the help of the Web-Search whos name may not be said out loud. Merry new Year!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thanks @Thomas Clemens
It could be any incompatibility by using Log4j 1.2.17-atlassian-3 in a Jira Server 7.2.2)?, I don´t think so, but if the case any of you have got any problems when installing that version of log4j.
Thanks!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.