We couldn't load all Actvitity tabs. Refresh the page to try again.
If the problem persists, contact your Jira admin.
IMPORTANT: JAC is a Public system and anyone on the internet will be able to view the data in the created JAC tickets. Please don’t include Customer or Sensitive data in the JAC ticket.
Uploaded image for project: 'Jira Software Data Center'
  1. Jira Software Data Center
  2. JSWSERVER-26146

Jira 9.12.14 LTS version installer is bundled with vulnerable Java version

    • Icon: Suggestion Suggestion
    • Resolution: Unresolved
    • None
    • Versions
    • None
    • 0
    • We collect Jira feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

      Problem

      the current LTS version of Jira (9.12.14) is bundled with Eclipse Temurin 17.0.7 which has been released in April 2023 and is affected by a multitude of vulnerabilities. Please refer to the following OpenJDK Vulnerability Advisories for details:

      17.0.7: https://openjdk.org/groups/vulnerability/advisories/2023-07-18
      17.0.8: https://openjdk.org/groups/vulnerability/advisories/2023-10-17
      17.0.9: https://openjdk.org/groups/vulnerability/advisories/2024-01-16
      17.0.10: https://openjdk.org/groups/vulnerability/advisories/2024-04-16
      17.0.11: https://openjdk.org/groups/vulnerability/advisories/2024-07-16
      17.0.12: https://openjdk.org/groups/vulnerability/advisories/2024-10-15

      Suggested Solution

      Please update the bundled JDK to the current version 17.0.13 as soon as possible.

      Why This Is Important

      It is important to keep to Jira LTS version within the compliance standards and without any security vulnerabilities.
      Also switching to a standalone JDK requires some manual effort if Atlassian doesn't bundle the Jira installer with Eclipse Temurin 17.0.13

      Workaround

      You can change the Java used by following the steps in How to change the Java version used by Jira Server and Data Center

            Loading...
            IMPORTANT: JAC is a Public system and anyone on the internet will be able to view the data in the created JAC tickets. Please don’t include Customer or Sensitive data in the JAC ticket.
            Uploaded image for project: 'Jira Software Data Center'
            1. Jira Software Data Center
            2. JSWSERVER-26146

            Jira 9.12.14 LTS version installer is bundled with vulnerable Java version

              • Icon: Suggestion Suggestion
              • Resolution: Unresolved
              • None
              • Versions
              • None
              • 0
              • We collect Jira feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

                Problem

                the current LTS version of Jira (9.12.14) is bundled with Eclipse Temurin 17.0.7 which has been released in April 2023 and is affected by a multitude of vulnerabilities. Please refer to the following OpenJDK Vulnerability Advisories for details:

                17.0.7: https://openjdk.org/groups/vulnerability/advisories/2023-07-18
                17.0.8: https://openjdk.org/groups/vulnerability/advisories/2023-10-17
                17.0.9: https://openjdk.org/groups/vulnerability/advisories/2024-01-16
                17.0.10: https://openjdk.org/groups/vulnerability/advisories/2024-04-16
                17.0.11: https://openjdk.org/groups/vulnerability/advisories/2024-07-16
                17.0.12: https://openjdk.org/groups/vulnerability/advisories/2024-10-15

                Suggested Solution

                Please update the bundled JDK to the current version 17.0.13 as soon as possible.

                Why This Is Important

                It is important to keep to Jira LTS version within the compliance standards and without any security vulnerabilities.
                Also switching to a standalone JDK requires some manual effort if Atlassian doesn't bundle the Jira installer with Eclipse Temurin 17.0.13

                Workaround

                You can change the Java used by following the steps in How to change the Java version used by Jira Server and Data Center

                        Unassigned Unassigned
                        8d241b947074 Baris Ilhan
                        Votes:
                        1 Vote for this issue
                        Watchers:
                        3 Start watching this issue

                          Created:
                          Updated:

                              Unassigned Unassigned
                              8d241b947074 Baris Ilhan
                              Votes:
                              1 Vote for this issue
                              Watchers:
                              3 Start watching this issue

                                Created:
                                Updated: