Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Jira Security advisory for CVE-2022-0540 - Authentication bypass in Seraph

Teresa Luis April 22, 2022

Hi, still very new to Jira.  I am not able to upgrade today so I need to do the workaround on this.  If I look at User-Installed Apps in my Manage Apps, that will be where any Marketplace apps are correct?  So if they are not listed there I don't need to worry about "List of affected Atlassian Marketplace apps" section.

 

Also, I disabled Mobile Plugin for Jira and can't find "Insight - Asset Management in that list either"  Could that be listed anywhere else?

 

Thanks for you help!

Teresa

 

1 answer

1 accepted

2 votes
Answer accepted
Robert Wen_Cprime_
Community Champion
April 22, 2022

Hello, @Teresa Luis !

1. Yes, compare the User-installed apps against the list of affected Atlassian Marketplace apps.  If you don't have any on the list, you're good!

2. Insight was recently bundled into Jira Service Management Data Center 8.15.  If you are on that version or later, you should upgrade.

Hope this helps!

serkan_sezer
Contributor
April 29, 2022

Hi,, If you have a list of affected apps, could you please share? thank you

Robert Wen_Cprime_
Community Champion
April 29, 2022

The official notice from Atlassian has the list of apps.  Here's the link: https://confluence.atlassian.com/jira/jira-security-advisory-2022-04-20-1115127899.html

Like serkan_sezer likes this

Suggest an answer

Log in or Sign up to answer