-
Suggestion
-
Resolution: Fixed
-
17
-
7
-
-
Problem Definition
Current embedded JRE has some vulnerabilities which have been resolved in critical security update Java 1.8.0.171. Many larger companies which have a dedicated security team will ask their JIRA system admin to update the Java version to the new critical security update. Which forces the JIRA system admin to sway away from sticking to the embedded version.
https://www.java.com/en/download/faq/release_changes.xml
Suggested Solution
Test and bundle with the latest Java 1.8.0.171 into the new update of JIRA.
Workaround
If the customer is requested to update Java before a new JIRA release with the required java update comes out, they can update their Java versions manually by following these KB articles;
- is duplicated by
-
JRASERVER-67824 Update JDK for Enterprise release to get fix for JDK-8144566: 'Custom HostnameVerifier disables SNI extension'
- Closed
- relates to
-
JRASERVER-65102 Update bundled Apache Tomcat due to security vulnerabilities
- Closed
-
CONFSERVER-54108 Embed latest java critical security update (1.8.0.161 or higher) into the next Confluence (sub)version
- Closed
-
RAID-908 Loading...
- is related to
-
BDEV-14523 Loading...
- mentioned in
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...