Skip to main content
Question

Jamf Pro 10.30.1 Security Upgrade

  • June 18, 2021
  • 42 replies
  • 254 views

Show first post

42 replies

Forum|alt.badge.img+1
  • New Contributor
  • June 21, 2021

I'm trying to access the account.jamf.com URL, and have a blank page since yesterday.
Can you ?
Can't open ticket, too.


  • June 21, 2021

deletet, because of double posted


Forum|alt.badge.img+3
  • New Contributor
  • June 21, 2021

Same here, I can not access the "My Assets" page, it's just blank


  • June 21, 2021

As many others, my "My Assets" page is blank, too. There ist no content and no update to version 10.30.1 available. I have tested with different browsers. No worry, it's only a security patch... no big thing at all....


Forum|alt.badge.img+10
  • Author
  • Employee
  • June 21, 2021

Update - Added the reserved CVE number to the above post. - CVE-2021-35037


AV_ITSupport
Forum|alt.badge.img+1
  • New Contributor
  • June 22, 2021

For all who have a blank page (We got this since about a week).
If you look at it it will show a cors error..
You can have a workaround with an extension like "Allow CORS: Access-Control-Allow-Origin" in Chrome.
It is really just a workaround till it is fixed..


Forum|alt.badge.img+10
  • Author
  • Employee
  • June 22, 2021

[Update] - document now reflects a resolution to an issue where some customers experienced an issue accessing Jamf Account subpages. As of 9 am CST, June 21, this issue has been resolved and everyone should have access to all Jamf Account pages.


Forum|alt.badge.img+3
  • New Contributor
  • June 23, 2021

Forum|alt.badge.img+17
  • Honored Contributor
  • June 23, 2021

@Aaron.Kiemele Is jamf going to address that only some customers got emails about this critical update? This isn't the first time this has happened.


jacob_bernardy
Forum|alt.badge.img+18

@CasperSally Thank you for the feedback. It is our absolute intent to communicate quickly and responsibly to those we believe may be potentially impacted by security vulnerabilities. In some cases, we have used filters on direct email communication to avoid unnecessary action or concern by those who have not been impacted. It is evident that this may not have worked correctly. Our team is working to remediate this urgently to ensure it does not happen again.


Forum|alt.badge.img+14
  • Valued Contributor
  • June 24, 2021

We're still running 10.28 but making arrangements to update to 10.30.1.

It was my understanding that Jamf was going to start making use of the announcements in the Resource Center found in the lower right hand side of the browser window. If that's the case, why is there no mention of 10.30.1? I only see mention of 10.30.

For security issues, in my opinion, Jamf should be blasting such announcements out via every avenue.


Forum|alt.badge.img+6
  • Contributor
  • June 25, 2021

@jhuls We got an email announcement on Friday 6/18/2021 but has been a real pain as they aren't sending regular email comms on releases anymore.


Forum|alt.badge.img+10
  • Author
  • Employee
  • June 25, 2021

[Update] - added clarification around potential exploitation and impact of URL redirection


Forum|alt.badge.img+13
  • Valued Contributor
  • June 28, 2021

So, I tried to U/G this weekend and had the following error upgrading from 10.28.0 to 10.29.0


Forum|alt.badge.img+18
  • Honored Contributor
  • June 28, 2021

@kerouak Same. I am working through re-testing the upgrade. It doesn't seem like Jamf has been able to give us a way to detect this BEFORE upgrade.


Forum|alt.badge.img+13
  • Valued Contributor
  • June 30, 2021

@dgreening

I have a support case open at present, keep an eye out and I'll update this post accordingly if I get a solution.


Forum|alt.badge.img+4
  • Contributor
  • July 2, 2021

For those of you that have upgraded to 10.30.1. Have you noticed any issues with devices "check-in" in your environment?