Skip to main content
Question

Jamf Pro 10.34.2 Now Available

  • December 17, 2021
  • 49 replies
  • 308 views

Forum|alt.badge.img+10
Hello Jamf Nation,
 
Today we're releasing an update for Jamf Pro that addresses critical security issues CVE-2021-44228 and CVE-2021-45046. For details on how we’re addressing these vulnerabilities across the Jamf platform, please see this Jamf Nation post. Because keeping our customers’ environments secure is of the utmost importance, we’ll continue to be very intentional about when and how we communicate. 
 
We strongly recommend that you upgrade to Jamf Pro 10.34.2 as soon as possible. Customers utilizing our cloud-based products have had the vulnerability mitigated through layered security controls. We are confident that these mitigations are effective against all known attacks. Out an abundance of caution, we are releasing Jamf Pro 10.34.2 to include log4j 2.16 and mitigate all currently known log4j vulnerabilities.
 
Please read the resolved issues section of the release notes for more information. Additional details on the resolved vulnerability will be made available on a future date to allow for Jamf Pro instances to be updated before full disclosure.
 
 
We will also be sending this information via email to primary technical contacts at affected organizations.
 
Thank you!

49 replies

Forum|alt.badge.img+11
  • Valued Contributor
  • December 17, 2021

tough time to take out the cloud when people are also trying to remediate log4j with Jamf. Hope this includes a way for Jamf to detect 3rd party log4j issues.


Forum|alt.badge.img

any ideas on ETA? This literally went down as we are enrolling several devices for EOD delivery 


Forum|alt.badge.img+2
  • New Contributor
  • December 17, 2021

Was there communication or notice for the cloud maintenance? The previous release note said that the cloud instance was mitigated already. Why are we doing this during the day now and not when 10.34.2 was first released? This action has disturbed my works on remediating Log4J with my security dept and my companies Mac and iOS provisioning. 


atomczynski11
Forum|alt.badge.img+18
  • Jamf Heroes
  • December 17, 2021

@ShadowGT 

I believe the original patch secured for version .15 which we have learned introduced their own vulnerabilities which version .16 patches.


Forum|alt.badge.img+2
  • New Contributor
  • December 17, 2021

@atomczynski11 That makes sense and thank you for the info,  but I'm more concerned about the unscheduled maintenance downtime during working hours.


Forum|alt.badge.img+3
  • New Contributor
  • December 17, 2021

This is unfortunate timing on the maintenance period. ETA please?


Forum|alt.badge.img+6
  • New Contributor
  • December 17, 2021

Agree here, the maintenance period should had been communicated before it even started.


TimWeed
Forum|alt.badge.img+1
  • New Contributor
  • December 17, 2021

No access to admin console. This is a major disruption to my hospital operations!


atomczynski11
Forum|alt.badge.img+18
  • Jamf Heroes
  • December 17, 2021

All good valid points.

I do belive they either saw it already being exploited or weighted the potential risk in future scheduling vs an operations disruptions and decided to go with the route they did.


CommandShiftK
Forum|alt.badge.img+4
  • Contributor
  • December 17, 2021

The timing kinda stinks, I was in the middle of a Tanium agent update deployment to my fleet...


Forum|alt.badge.img+18
  • Valued Contributor
  • December 17, 2021

This is completely unacceptable. Zero communication of a "scheduled" maintenance in the middle of the work day? If any of us did this, we'd be shown the door. There had better be a good explanation for this. 


Forum|alt.badge.img+6
  • New Contributor
  • December 17, 2021

Dang near had a heart attack when one of my techs messaged me "Hey is our Jamf portal down?"

 

Glad we're getting Log4J mitigation, but it would've been nice to get some advanced warning on this so I could alert my team 🙂


geoffreykobrien
Forum|alt.badge.img+9
  • Valued Contributor
  • December 17, 2021

4pm on a Friday, thanks JAMF.....


CommandShiftK
Forum|alt.badge.img+4
  • Contributor
  • December 17, 2021

.


donmontalvo
Forum|alt.badge.img+36
  • Hall of Fame
  • December 17, 2021

When it comes to mitigating vulnerabilities, one thing is for sure, Jamf is bad @$$!


apizz
Forum|alt.badge.img+15
  • Honored Contributor
  • December 17, 2021

Yeah this upgrade is pretty bad timing for us as well ... Pressure changes everything and it appears we customers get the short end of the stick 😕😕


Forum|alt.badge.img
  • New Contributor
  • December 17, 2021

Ouch. I get why JAMF would want to get this patched ASAP. But just a bit of communication would have been nice so we can prepare on what we can and can't do during the update.


donmontalvo
Forum|alt.badge.img+36
  • Hall of Fame
  • December 17, 2021

Some links that might find a home in your browser bookmarks, or maybe a Jamf FAQ:

server-tools.jar
https://archive.services.jamfcloud.com/#jamf-pro-server-tools/release/latest/gui/

Jamf Pro Server Tools
https://account.jamf.com/products/other/jamf-pro-server-tools

Jamf Pro
https://account.jamf.com/products/jamf-pro


Forum|alt.badge.img+4
  • New Contributor
  • December 17, 2021

No communication regarding a mid afternoon maintenance window on a weekday?  Ouch.


armentrout
Forum|alt.badge.img+4
  • New Contributor
  • December 17, 2021

I was in the middle of wiping several machines campus wide, I got get some water and come back to the admin portal being down.  Helluva way to not get ahead.  Oh well, hopefully it's back up soon.

 


Forum|alt.badge.img+5
  • New Contributor
  • December 17, 2021

appreciate the patch, but would really loved more email communication on when this was happening...


Forum|alt.badge.img+2
  • New Contributor
  • December 17, 2021

Really disappointed about the timing and lack of warning here. Doing enrollments and I was already cutting it close on an EOD deadline that I now won't be able to meet. Business will be negatively impacted.


bgrant11
Forum|alt.badge.img+4
  • Contributor
  • December 17, 2021

I am getting blown up by co-workers and will now have to have meeting about this. If the patch took 15 mins fine, but this? It's been over 2 hours in the middle of the work day! 


Forum|alt.badge.img

Is there an estimated return to service? It’s been down for hours. 


Forum|alt.badge.img+17
  • Valued Contributor
  • December 17, 2021

Looks like they were planning for a long one per the (separate!!!???) maintenance email: