Uploaded image for project: 'Jira Software Data Center'
  1. Jira Software Data Center
  2. JSWSERVER-26146

Jira 9.12.14 LTS version installer is bundled with vulnerable Java version

    • Icon: Suggestion Suggestion
    • Resolution: Unresolved
    • None
    • Versions
    • None
    • 0
    • 2
    • We collect Jira feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

      Problem

      the current LTS version of Jira (9.12.14) is bundled with Eclipse Temurin 17.0.7 which has been released in April 2023 and is affected by a multitude of vulnerabilities. Please refer to the following OpenJDK Vulnerability Advisories for details:

      17.0.7: https://openjdk.org/groups/vulnerability/advisories/2023-07-18
      17.0.8: https://openjdk.org/groups/vulnerability/advisories/2023-10-17
      17.0.9: https://openjdk.org/groups/vulnerability/advisories/2024-01-16
      17.0.10: https://openjdk.org/groups/vulnerability/advisories/2024-04-16
      17.0.11: https://openjdk.org/groups/vulnerability/advisories/2024-07-16
      17.0.12: https://openjdk.org/groups/vulnerability/advisories/2024-10-15

      Suggested Solution

      Please update the bundled JDK to the current version 17.0.13 as soon as possible.

      Why This Is Important

      It is important to keep to Jira LTS version within the compliance standards and without any security vulnerabilities.
      Also switching to a standalone JDK requires some manual effort if Atlassian doesn't bundle the Jira installer with Eclipse Temurin 17.0.13

      Workaround

      You can change the Java used by following the steps in How to change the Java version used by Jira Server and Data Center

            [JSWSERVER-26146] Jira 9.12.14 LTS version installer is bundled with vulnerable Java version

            SET Analytics Bot made changes -
            Support reference count New: 2
            SET Analytics Bot made changes -
            UIS Original: 1 New: 0
            SET Analytics Bot made changes -
            UIS New: 1
            Baris Ilhan created issue -

              Unassigned Unassigned
              8d241b947074 Baris Ilhan
              Votes:
              1 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: