Hi Jamf Nation,
We recently became aware of a security vulnerability that impacts versions of Jamf Pro 9.4 and later. To mitigate the issue, we are making Jamf Pro 10.15.1 available today.
This vulnerability does not pose a risk to private data or managed devices. It does have the potential to impact the integrity and availability of your web server.
Cloud customers will be automatically upgraded during the upgrade window outlined below. Premium and Custom customers can contact their Customer Success representative to schedule an upgrade. On-premise customers can download the installer via the My Assets page on Jamf Nation.
Details we are able to provide at this time are below. If you have additional questions, please contact your Jamf representative or leave a comment below.
Thank you,
Garrett
Update #1: Sept 29, 2019
Jamf Pro 10.13.1 - Now Available
Yesterday we disclosed a critical security vulnerability that impacts all Jamf Pro instances from 9.4.0 through 10.15.0 and made Jamf Pro 10.15.1 available to mitigate the issue. Today we are making an additional build available for customers that are unable to upgrade directly to the latest Jamf Pro release.
We recognize that some customers might have specific constraints that prevent them from immediately upgrading to 10.15.1. To give those customers an immediate path to mitigation, we’re making 10.13.1 generally available today.
Because all standard cloud customers are already upgraded to 10.15.1 (and protected from the known vulnerability), 10.13.1 is only available to customers that control their instance version, such as On-Premise and Premium Cloud.
To upgrade to Jamf Pro 10.13.1, please contact our Customer Success team at success@jamf.com. We have the capacity this weekend should you want to upgrade immediately.
Frequently Asked Questions
What is the issue?
We recently became aware of a critical security vulnerability that could potentially impact any Jamf Pro instance. Jamf Pro 10.15.1 mitigates this issue. This issue does not impact any other Jamf products.
Why is this important?
We take security very seriously and want to move quickly to give you every option to upgrade and stay secure. This vulnerability does not pose a risk to private data or managed devices. It does have the potential to impact the integrity and availability of your web server.
Is my instance impacted?
All Jamf Pro instances running version 9.4 or later are impacted and should be upgraded to 10.15.1 as soon as possible.
When will my standard cloud instance be upgraded?
Cloud upgrades began during a global cloud maintenance window today (Sept 28) at 1700 UTC and will continue through 0500 UTC on Sept 29.
When will my Premium Cloud instance be upgraded?
Please contact success@jamf.com to schedule an upgrade for your environment.
How can I secure my on-premise instance?
An installer is available now in the My Assets page on Jamf Nation.


