Critical Vulnerability Notification: SRJIRA-8436
Understand the critical security vulnerability affecting ScriptRunner for Jira Data Center and how to remediate it.
Overview
A critical security vulnerability, with CVSSv4 score 10, has been identified affecting ScriptRunner for Jira Data Center versions up to and including 8.60.0, 9.0-9.35.1 and 10.0 - 10.11.2 and ScriptRunner for Jira Server versions up to and including 8.43.0. This does not affect ScriptRunner for Jira Cloud.
Please immediately upgrade to the latest version available for your Jira instance to patch this vulnerability.
What happened?
We discovered a vulnerability while performing a security review, prompted by a related report submitted from a third-party researcher. At the time of writing, we have no indication that this vulnerability has been exploited.
What do I need to do?
You must upgrade to the latest version of ScriptRunner available for your Jira instance as soon as possible.
Data Center
An upgrade for Data Center is available now.
Data Center latest versions:
- ScriptRunner 10.12.0 compatible with Jira 11.0.0 - 11.3.7
- ScriptRunner 9.36.1 compatible with Jira 10.0.0 - 10.7.4
- ScriptRunner 8.62.1 compatible with Jira 8.20.0 - 9.17.5
Server
An upgrade for Server is available now.
Server latest version:
- ScriptRunner 8.62.2 compatible with Jira Server 8.20.0 - 9.17.5
Learn how to access the upgrade and how to update your version of ScriptRunner for Jira using this guide.
If you have an Atlassian partner, you can reach out to them for assistance with this upgrade.
If you do not have an Atlassian partner, you can reach out to our support team.
What if I can't upgrade?
The recommended workaround for those who are unable to upgrade immediately is to isolate your instance from untrusted networks until you are able to upgrade.
If this solution is not workable for your setup or you do not anticipate being able to upgrade for any reason, please reach out to our support team for further assistance.
If you have any other questions or require further support, please raise a ticket here.