Uploaded image for project: 'Jira Server and Data Center'
  1. Jira Server and Data Center
  2. JRASERVER-66241

Embed latest java critical security update (1.8.0.171 or higher) into the next JIRA (sub)version

    XMLWordPrintable

    Details

    • Feedback Policy:
      We collect Jira feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.
    • Current Status:
      Hide
      Atlassian Update – 21 December 2018

      Dear Jira users,

      We’re glad to announce that this issue will be addressed in our upcoming 8.0 release.

      You can find more details about our 8.0 beta release here — https://community.developer.atlassian.com/t/beta-for-jira-8-0-is-up-for-grabs/25588

      Looking forward to your feedback!

      Kind regards,
      Syed Masood
      Product Manager, Jira Server and Data Center

      Show
      Atlassian Update – 21 December 2018 Dear Jira users, We’re glad to announce that this issue will be addressed in our upcoming 8.0 release. You can find more details about our 8.0 beta release here — https://community.developer.atlassian.com/t/beta-for-jira-8-0-is-up-for-grabs/25588 Looking forward to your feedback! Kind regards, Syed Masood Product Manager, Jira Server and Data Center
    • UIS:
      17

      Description

      Problem Definition

      Current embedded JRE has some vulnerabilities which have been resolved in critical security update Java 1.8.0.171. Many larger companies which have a dedicated security team will ask their JIRA system admin to update the Java version to the new critical security update. Which forces the JIRA system admin to sway away from sticking to the embedded version.

      https://www.java.com/en/download/faq/release_changes.xml

      Suggested Solution

      Test and bundle with the latest Java 1.8.0.171 into the new update of JIRA.

      Workaround 

      If the customer is requested to update Java before a new JIRA release with the required java update comes out, they can update their Java versions manually by following these KB articles;

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                psuwala Piotr Suwala
                Reporter:
                sdegroot@atlassian.com Steven de Groot
              • Votes:
                7 Vote for this issue
                Watchers:
                19 Start watching this issue

                Dates

                • Due:
                  Created:
                  Updated:
                  Resolved: