Clearvision News & Events
We’re Hiring!

Are you interested in joining a fast growing and dynamic company?

Clearvision are recruiting for a number of positions as we continue to expand at a rapid rate. See more details below for the exciting opportunities currently available.

  • Technical Consultant - software change and configuration management consultant with good understanding of open source.
  • Software Engineer - experienced software engineer working on plugins and existing tool, ideally has experience of working directly with customers.
  • Software Engineer + Support (based in Australia or neighbouring countries) - Exciting opportunity for a software engineer to assist the UK development and 24 hour support operations.
  • Experienced Sales - looking for an ambitious, enthusiastic and pro-active IT sales person to build existing customer relationships alongside the closure of new leads and enquiries for IT software and services.

Please contact us for more details.

 
Security Alert: Atlassian FishEye/Crucible

Security Alert: Atlassian FishEye/Crucible 2.0 to 2.7.8 affected

Please be aware of the following security alert issued by Atlassian on 31 January 2012.

We are writing to inform you of a recently discovered security vulnerability in Atlassian FishEye and Crucible. This security vulnerability is rated as CRITICAL. To fix this vulnerability, you should follow the instructions in the security advisory below. Enterprise Hosted customers should request an upgrade by raising a support request at http://support.atlassian.com. Neither JIRA Studio nor Atlassian OnDemand are vulnerable to any of the issues described in this advisory.

For your convenience, we have included the entire security advisory in this email. To view the online version of this security advisory, please go to http://confluence.atlassian.com/display/CRUCIBLE/FishEye+and+Crucible+Security+Advisory+2012-01-31.

If you have any questions or concerns about this security vulnerability or about our policy of disclosure of security vulnerabilities, please visit our page on Atlassian Security Policies (http://confluence.atlassian.com/display/Support/Atlassian+Security+Policies) or raise a support request at http://support.atlassian.com/.

*** Security Advisory ***

This advisory discloses a CRITICAL security vulnerability that we have found in versions of FishEye and Crucible from 2.0 up to and including 2.7.8. You need to upgrade your existing FishEye and Crucible installations to fix these vulnerabilities. Enterprise Hosted customers should request an upgrade by raising a support request at http://support.atlassian.com/ in the "Enterprise Hosting Support" project. Neither FishEye nor Crucible in Studio and Atlassian OnDemand are vulnerable to any of the issues described in this advisory.

Atlassian is committed to improving product security. The vulnerabilities listed in this advisory have been discovered by Atlassian, unless noted otherwise. The reporter may also have requested that we do not credit them.

If you have questions or concerns regarding this advisory, please raise a support request at http://support.atlassian.com/.

*Code Injection Vulnerability*

- Severity -- Atlassian rates the severity level of this vulnerability as CRITICAL, according to the scale published in Severity Levels for Security Issues (http://confluence.atlassian.com/display/CRUCIBLE/Severity+Levels+for+Security+Issues). The scale allows us to rank the severity as critical, high, medium or low.

- Description -- We have identified and fixed a code injection vulnerability in FishEye and Crucible caused by an underlying vulnerability in the third-party Webwork 2 framework. This vulnerability allows an attacker to run arbitrary Java code on a FishEye/Crucible server with user privileges of the FishEye/Crucible process. This vulnerability is a variant of a recently disclosed Struts2 vulnerability (https://www.sec-consult.com/files/20120104-0_Apache_Struts2_Multiple_Critical_Vulnerabilities.txt). The vulnerability exists in pages of FishEye and Crucible accessible only by users with administrative privileges. It can be exploited with use of social engineering, e.g. by having the administrator click on a specially crafted link. The maintainer of the original library can be contacted at http://struts.apache.org/

- Vulnerability -- The list below describes the FishEye and Crucible versions and the specific functionality affected by the command injection vulnerability:

1) Command injection vulnerability: affects FishEye and Crucible versions 2.0 up to and including 2.7.8; fixed in versions 2.6.7 and 2.7.9. See tracking issue FE-3891 (https://jira.atlassian.com/browse/FE-3891).

- Risk Mitigation -- We recommend that you upgrade your FishEye and Crucible installations to fix this vulnerability. Alternatively, if you are not in a position to upgrade immediately and you judge it necessary, you can restrict access to your instance of FishEye/Crucible by using a firewall.

- Fix -- FishEye and Crucible 2.6.7, 2.7.9 and later versions fix this issue. View the tracking issue above for information on fix versions. For a full description of the latest version of FishEye and Crucible, see the FishEye (http://confluence.atlassian.com/display/FISHEYE/FishEye+Release+Notes) and Crucible (http://confluence.atlassian.com/display/CRUCIBLE/Crucible+Release+Notes) release notes. You can download the latest versions from the FishEye (http://www.atlassian.com/software/fisheye/FishEyeDownloadCenter.jspa) and Crucible (http://www.atlassian.com/software/crucible/CrucibleDownloadCenter.jspa) download centres. There are no patches available for these issues.

Discover Clearvision's exclusive offerings on Atlassian for new and existing users: http://www.clearvision-cm.com/clearvision-atlassian-experts.html.

 
Security Alert: Atlassian Bamboo

Security Alert: Atlassian Bamboo versions up through 3.4.2 affected

Please be aware of the following security alert issued by Atlassian on 31 January 2012.

We are writing to inform you of two recently discovered security vulnerabilities in Atlassian Bamboo. Both of these security vulnerabilities are rated as CRITICAL. To fix these vulnerabilities, you should follow the instructions in the security advisory below.

Enterprise Hosted customers should request an upgrade by raising a support request athttp://support.atlassian.com. Neither Bamboo Studio nor OnDemand are vulnerable to any of the issues described in this advisory.

For your convenience, we have included the entire security advisory in this email. To view the online version of this security advisory, please go to http://confluence.atlassian.com/display/BAMBOO/Bamboo+Security+Advisory+2012-01-31.

If you have any questions or concerns about this security vulnerability or about our policy of disclosure of security vulnerabilities, please visit our page on Atlassian Security Policies (http://confluence.atlassian.com/display/Support/Atlassian+Security+Policies) or raise a support request at http://support.atlassian.com/.

*** Security Advisory ***

This advisory discloses two CRITICAL security vulnerabilities that exist in versions of Bamboo up to and including 3.4.2. You need to upgrade your existing Bamboo installations to fix these vulnerabilities.

Enterprise Hosted customers should request an upgrade by raising a support request athttp://support.atlassian.com/ in the "Enterprise Hosting Support" project. Neither Bamboo Studio nor Atlassian OnDemand are vulnerable to any of the issues described in this advisory.

Atlassian is committed to improving product security. The vulnerabilities listed in this advisory have been discovered by Atlassian, unless noted otherwise. The reporter may also have requested that we do not credit them. If you have questions or concerns regarding this advisory, please raise a support request athttp://support.atlassian.com/.

*Code Injection Vulnerability*

- Severity -- Atlassian rates the severity level of this vulnerability as CRITICAL, according to the scale published in http://confluence.atlassian.com/display/BAMBOO/Severity+Levels+for+Security+Issues. The scale allows us to rank the severity as critical, high, medium or low.

- Description -- We have identified and fixed a vulnerability in Bamboo caused by a combination of issues in third-party libraries, including FreeMarker template library, used in Bamboo. This vulnerability allows an attacker to access any files on Bamboo server that are readable by the Bamboo server process. The attacker does not need to authenticate in order to exploit the vulnerability. The vulnerability is related to the previously disclosed FreeMarker issue. The vulnerability does not affect Bamboo installations using Tomcat as will usually be present only in Bamboo standalone.

- Vulnerability -- The list below describes the Bamboo version and the specific functionality affected by the Webwork 2 vulnerability.

1) Webwork 2 vulnerability: affects Bamboo versions up to and including 3.4.2; fixed in Bamboo versions 3.3.4 and 3.4.3. See tracking issue https://jira.atlassian.com/browse/BAM-10627.

- Risk Mitigation -- We highly recommend that you upgrade your Bamboo installation to fix these vulnerabilities. Alternatively, if you are not in a position to upgrade immediately and you judge it necessary, you can restrict access to your instance of Bamboo by using a firewall.

- Fix -- Bamboo 3.4.3 and later versions fix this issue. View the tracking issue above for information about fix versions. For a full description of the latest version of Bamboo, see the release notes (http://confluence.atlassian.com/display/BAMBOO/Bamboo+Release+Notes). You can download the latest version of Bamboo from the Bamboo download centre (http://www.atlassian.com/software/bamboo/BambooDownloadCenter.jspa). If you cannot upgrade to the latest version of Bamboo, you can patch your existing installation using the patch listed below. We strongly recommend upgrading and not patching.

- Patches -- A binary patch for the Webwork 2 vulnerability is available for Bamboo versions 3.0 and later. The patch (SimpleConversionErrorInterceptor.zip) is attached to the BAM-10627 tracking issue (https://jira.atlassian.com/browse/BAM-10627).

- Applying the patch -- If you are using Bamboo 3.0 or later:

1) Download the SimpleConversionErrorInterceptor.zip file that is attached to the BAM-10627 issue (https://jira.atlassian.com/browse/BAM-10627).

2) Stop Bamboo.

3) Make a backup of the directory.

4) Create directories com/atlassian/bamboo/ww2/interceptors in the WEB-INF/classes directory, which can be found within your Bamboo installation.

5) Unzip SimpleConversionErrorInterceptor.zip into com/atlassian/bamboo/ww2/interceptors:

mkdir -p com/atlassian/bamboo/ww2/interceptors cd com/atlassian/bamboo/ww2/interceptors unzip SimpleConversionErrorInterceptor.zip

6) Add a reference to the new SimpleConversionErrorInterceptor in the xwork.xml file in WEB-INF/classes:

...

class="com.atlassian.bamboo.ww2.interceptors.SimpleConversionErrorInterceptor"/>

...

7) Restart Bamboo.

*Arbitrary File Disclosure Vulnerability*

- Severity -- Atlassian rates the severity level of this vulnerability as CRITICAL, according to the scale published in http://confluence.atlassian.com/display/BAMBOO/Severity+Levels+for+Security+Issues. The scale allows us to rank the severity as critical, high, medium or low.

- Description -- We have identified and fixed a vulnerability in Bamboo caused by an underlying vulnerability in the third-party FreeMarker template library used in Bamboo. This vulnerability allows an attacker to access any files on Bamboo server that are readable by the Bamboo server process. The attacker does not need to authenticate in order to exploit the vulnerability. The vulnerability is related to the previously disclosed FreeMarker issue (http://freemarker.sourceforge.net/docs/versions_2_3_17.html#autoid_137). The maintainer of the original library can be contacted at http://freemarker.sourceforge.net/

- Vulnerability -- The list below describes the Bamboo versions and the specific functionality affected by the arbitrary file disclosure vulnerability.

1) Vulnerability in the third-party FreeMarker template library: affects Bamboo versions up to and including 3.4.2; fixed in Bamboo versions 3.3.4 and 3.4.3. See tracking issuehttps://jira.atlassian.com/browse/BAM-10628.

- Risk Mitigation -- We recommend that you upgrade your Bamboo installation to fix this vulnerability. Alternatively, if you are not in a position to upgrade immediately and you judge it necessary, you can restrict access to your instance of Bamboo by using a firewall.

- Fix -- Bamboo 3.4.3 and later versions fix this issue. View the tracking issue above for information about fix versions. For a full description of the latest version of Bamboo, see the release notes (http://confluence.atlassian.com/display/BAMBOO/Bamboo+Release+Notes). You can download the latest version of Bamboo from the Bamboo download centre (http://www.atlassian.com/software/bamboo/BambooDownloadCenter.jspa). If you cannot upgrade to the latest version of Bamboo, you can patch your existing installation using the patch listed below. We strongly recommend upgrading and not patching.

- Patches -- A binary patch for the FreeMarker vulnerability is available for Bamboo versions 3.0 and later. The patch (freemarker-2.3.16-atlassian-11.jar) is attached to the BAM-10628 tracking issue (https://jira.atlassian.com/browse/BAM-10628).

- Applying the patch -- If you are using Bamboo 3.0 or later:

1) Download the freemarker-2.3.16-atlassian-11.jar file that is attached to the BAM-10628 issue (https://jira.atlassian.com/browse/BAM-10628).

2) Stop Bamboo.

3) Make a backup of the directory.

4) Copy freemarker-2.3.16-atlassian-11.jar to WEB-INF/lib.

5) Move the existing freemarker jar to a backed up location.

6) Restart Bamboo.

Discover Clearvision's exclusive offerings on Atlassian for new and existing users: http://www.clearvision-cm.com/clearvision-atlassian-experts.html.

 
JIRA and Zendesk

JIRA and Zendesk - Are you making the most of the integration?

If your organisation uses Zendesk for external support and Atlassian JIRA for internal issue tracking, are you making the most of the link between them? That's exactly what we do here at Clearvision. When an end user raises a request for tool enhancement, we can convert that request into a JIRA ticket with just a few simple clicks and begin tracking work on it immediately. Our developers are constantly aware of customer requests and any internal decisions are automatically passed onto the customer through their Zendesk tickets.

Zendesk for JIRA 2.0 allows you to:

  • Create a new JIRA issue from a Zendesk ticket.
  • Link a ticket to an existing JIRA issue.
  • Map Zendesk ticket fields to JIRA issue fields including:
    • Bi-directional or uni-directional mappings.
    • Public and private fields or comments.
  • Automatically resolve Zendesk tickets by resolving JIRA issues.
  • Link multiple Zendesk help desks to a single JIRA account.

Contact us now to understand how we can help you make the most of your Zendesk and JIRA integration.

Contact Us
 
Migrating to Git

Migrating to Git – Questions to Consider

The requirement to migrate to open source Git is one that’s becoming increasingly more popular. Migrations of this nature can be relatively complex and often introduce various challenges. The following survey highlights specific questions to consider when planning a migration to Git.

What sort of results would you expect from a Git migration?

Take Survey

 
<< Start < Prev 1 2 3 4 5 6 7 8 9 10 Next > End >>

Page 1 of 23