Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

security advisory versions affected

Alicia Pena
Contributor
April 27, 2022

This Jira security advisory initially released 4/20/22 then updated with additional advisories for plugins shows fixed in 8.20.x>=8.20.6 .  But we’re staging 8.20.8 for our next long term support version.  Should we assume it’s fixed in all the . releases after .6 too?  https://confluence.atlassian.com/jira/jira-security-advisory-2022-04-20-1115127899.html?s[…]l-2020_EML-12929&utm_medium=email&utm_source=alert-email

3 answers

0 votes
serkan_sezer
Contributor
April 29, 2022

Hi @Andy Heinzer , we are using version 8.20.1. But I'm having confusion with the rankings in the announcement request. Is version 8.20.1 immune from the threat? Do we need to upgrade?

https://jira.atlassian.com/browse/JRASERVER-73650

@Alicia Pena thank you for the title

Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
April 29, 2022

No, 8.20.1 is not immune from this security advisory.  8.20.x is part of our Long Term Support releases.  Yes, you should upgrade to 8.20.6 (or a higher version within the 8.20.x line) in order to resolve this.

Like serkan_sezer likes this
0 votes
Alicia Pena
Contributor
April 27, 2022

Nevermind. I was misreading it.  

0 votes
Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
April 27, 2022

Within the 8.20.x line, yes, the fix is contained in all the subsequent 8.20 versions starting with 8.20.6 and higher.  So yes, 8.20.8 will also contain this fix.

Suggest an answer

Log in or Sign up to answer