HomeSecurityAtlassian fixes flaws in Bitbucket, Confluence, Jira

Atlassian fixes flaws in Bitbucket, Confluence, Jira

Atlassian has announced security updates that resolve six high-severity flaws in its Bitbucket, Confluence , and Jira Service Management products.

See also: Atlassian patches multiple high-severity vulnerabilities

Atlassian vulnerabilities

The Bitbucket Data Center and server updates resolve CVE-2024-21147 , a high-severity flaw in the Java Runtime Environment (JRE) that could lead to unauthorized access and compromise of critical data.

Oracle released patches for this bug as part of the July 2024 CPU, and Atlassian included the patches in Bitbucket Data Center and server versions 9.2.1, 8.19.10 , and 8.9.20.

Confluence Data Center and server updates resolve four high-severity issues, including two in the Moment.js JavaScript date library that were publicly disclosed in 2022 .

The two Atlassian security flaws, identified as CVE-2022-24785 and CVE-2022-31129, are described as path traversal and ReDoS (Regular Expression Denial of Service) that can be exploited without authentication.

See also: Godzilla Fileless Backdoor exploits Atlassian Confluence vulnerability

The company also announced patches for CVE-2024-4367, an XSS flaw that could allow attackers to execute arbitrary HTML or JavaScript code in a user's browser, and for CVE-2024-29131, an Apache Commons configuration flaw that could lead to DoS.

Atlassian fixes flaws in Bitbucket, Confluence, Jira

Confluence Data Center and Server versions 7.19.26, 8.0.0, 8.5.11, 8.9.3 , and all versions after 9.0.0 contain fixes for these vulnerabilities.

The security updates released for the Atlassian Jira Service Management Data Center and the server address CVE-2024-7254, a Protobuf buffer overflow vulnerability that could allow attackers to affect the service availability.

Fixes for this bug were included in versions 5.12.14, 5.17.4 , and 10.1.1 of the Jira Service Management Data Center and Server.

See also: Atlassian Confluence vulnerability used for crypto-mining attacks

Security updates are critical to maintaining the integrity and security of computer systems and applications. They involve the regular distribution of patches or fixes that address vulnerabilities found in software programs or operating systems. These updates protect against potential cyber threats ,such as malware or unauthorized access, by closing security gaps that hackers may exploit. In addition, security updates ensure compliance with privacy regulations and help protect sensitive information, thereby reducing the risk of data breaches. Regularly installing security updates is a preventative measure that contributes significantly to the overall security posture of any digital environment.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS