Skip to main content
Question

JSS Spring Board Vulnerability

  • January 13, 2021
  • 4 replies
  • 25 views

Forum|alt.badge.img+3

Spring Board vulnerability found in jar file for JSS/Backups/BackupID/Tomcat/* . Anyone else ran into this issue and how did they address?

4 replies

sdagley
Forum|alt.badge.img+25
  • Jamf Heroes
  • January 13, 2021

@user-mfobssCWjV That's a backup directory, which would seem to indicate a previously installed version of your JSS had a vulnerability. If that's the only directory triggering a warning on your server then your current install has the fixed version.


Forum|alt.badge.img+3
  • Author
  • New Contributor
  • January 14, 2021

Thank you for the response, I figured as much but wanted to be sure.


donmontalvo
Forum|alt.badge.img+36
  • Hall of Fame
  • January 15, 2021

We usually purge that folder (usually move to another location) after a few days go by without any Jamf Pro server problems.


Forum|alt.badge.img+3
  • New Contributor
  • January 15, 2021

For spring-core it's only one file, so deleting it in the backup is perfectly fine. However the backup will also have many other subsystems, especially an older Tomcat, so you're likely to get pinged on that.
After every update, I manually go in and tar the backup directory, eliminating the possibility any binaries there could be (mis)used.