Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Customers who have upgraded Jira to a fixed version mentioned on the Atlassian Security Advisory or upgraded Xporter for Jira Server & Data Center to version 6.9.9 or higher are not affected.

Customers who are on any of the affected versions, upgrade your Jira or Xporter for Jira Server & Data Center installations immediately to fix this vulnerability.

Severity

The vulnerability is rated as critical, according to the CVSS Version 3.


Description

Jira and Jira Service Management are vulnerable to an authentication bypass in its web authentication framework, Jira Seraph.

...

We recommend the upgrade of Jira as mentioned on the Atlassian Security Advisory so all apps in your instance are protected against CVE-2022-0540. As an alternative, Xporter released the 6.9.9 to the Atlassian Marketplace which fixes the vulnerability.

What You Need to Do

Upgrade

You  You can upgrade to the latest version of Xporter for Jira Server & Data Center using the Universal Plugin Manager as explained in Updating apps

...