-
Suggestion
-
Resolution: Answered
-
None
-
1
-
I would like to check whether Jira is affected by the recent security vulnerability issues TOMCAT AJP CNVD-2020-10487/CVE-2020-1938.
If yes, please suggest the Jira version to be upgraded.
thanks.
- is cloned from
-
JSDSERVER-6768 Jira Service Desk Security Vulnerability Tomcat AJP CNVD-2020-10487/CVE-2020-1938
- Closed
- relates to
-
JRASERVER-70993 The version of Apache Tomcat included with Jira Server is affected by CVE-2020-1935, CVE-2020-1938, CVE-2019-17569
-
- Closed
-
-
RAID-1987 You do not have permission to view this issue
- mentioned in
-
Page Failed to load
Hi f25acc213138 / i.murphy439501242,
Please see https://confluence.atlassian.com/adminjiraserver/configuring-apache-reverse-proxy-using-the-ajp-protocol-938847753.html
In summary, our products do not use AJP connectors by default - if you have not configured your instance to use the AJP connector, it is not vulnerable to the Ghostcat CVE.
Linked is a guide for customers who wish to use AJP anyway, but see the notes at the top of the page:
and