Atlassian has announced security updates that resolve six high-severity flaws in its Bitbucket, Confluence , and Jira Service Management products.
See also: Atlassian patches multiple high-severity vulnerabilities

The Bitbucket Data Center and server updates resolve CVE-2024-21147 , a high-severity flaw in the Java Runtime Environment (JRE) that could lead to unauthorized access and compromise of critical data.
Oracle released patches for this bug as part of the July 2024 CPU, and Atlassian included the patches in Bitbucket Data Center and server versions 9.2.1, 8.19.10 , and 8.9.20.
Confluence Data Center and server updates resolve four high-severity issues, including two in the Moment.js JavaScript date library that were publicly disclosed in 2022 .
The two Atlassian security flaws, identified as CVE-2022-24785 and CVE-2022-31129, are described as path traversal and ReDoS (Regular Expression Denial of Service) that can be exploited without authentication.
See also: Godzilla Fileless Backdoor exploits Atlassian Confluence vulnerability
The company also announced patches for CVE-2024-4367, an XSS flaw that could allow attackers to execute arbitrary HTML or JavaScript code in a user's browser, and for CVE-2024-29131, an Apache Commons configuration flaw that could lead to DoS.

Confluence Data Center and Server versions 7.19.26, 8.0.0, 8.5.11, 8.9.3 , and all versions after 9.0.0 contain fixes for these vulnerabilities.
The security updates released for the Atlassian Jira Service Management Data Center and the server address CVE-2024-7254, a Protobuf buffer overflow vulnerability that could allow attackers to affect the service availability.
Fixes for this bug were included in versions 5.12.14, 5.17.4 , and 10.1.1 of the Jira Service Management Data Center and Server.
See also: Atlassian Confluence vulnerability used for crypto-mining attacks
Security updates are critical to maintaining the integrity and security of computer systems and applications. They involve the regular distribution of patches or fixes that address vulnerabilities found in software programs or operating systems. These updates protect against potential cyber threats ,such as malware or unauthorized access, by closing security gaps that hackers may exploit. In addition, security updates ensure compliance with privacy regulations and help protect sensitive information, thereby reducing the risk of data breaches. Regularly installing security updates is a preventative measure that contributes significantly to the overall security posture of any digital environment.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
