Virtual Event: Threat Detection & Incident Response Summit - Watch Now
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Atlassian Patches Critical Vulnerabilities in Confluence, Crowd

Atlassian has released patches for 12 critical- and high-severity vulnerabilities in Bamboo, Bitbucket, Confluence, Crowd, and Jira.

Atlassian security updates

Atlassian this week announced the rollout of patches for 12 critical- and high-severity vulnerabilities in its Bamboo, Bitbucket, Confluence, Crowd, and Jira products.

The company released fixes for five critical-severity issues in Confluence Data Center and Server and Crowd Data Center and Server that were discovered in third-party dependencies used within the two products.

Updates released for Confluence Data Center and Server address two critical flaws in Apache Tomcat. Tracked as CVE-2024-50379 and CVE-2024-56337 (CVSS score of 9.8), the two issues could be exploited by unauthenticated attackers to achieve remote code execution (RCE), the company warns.

The two flaws were addressed in Crowd Data Center and Server as well, along with a third critical bug in Apache Tomcat, tracked as CVE-2024-52316 (CVSS score of 9.8). Also exploitable by unauthenticated attackers, the defect could lead to authentication bypass, Atlassian says.

The updates for Crowd also resolve a high-severity denial of service (DoS) vulnerability in ua-parser-js, which is tracked as CVE-2022-25927, Atlassian notes in its February 2025 security bulletin.

The company rolled out fixes for two high-severity DoS flaws in Bamboo Data Center and Server, affecting Protocol Buffers (CVE-2024-7254) and the XStream library (CVE-2024-47072), and for a high-severity RCE bug in Bitbucket Data Center and Server, impacting the Java SDK of Apache Avro (CVE-2024-47561).

Advertisement. Scroll to continue reading.

The DoS security defect in Protocol Buffers was also addressed in Jira Data Center and Server, Atlassian announced.

The company makes no mention of any of these vulnerabilities being exploited against its products, but urges customers to update their installations as soon as possible.

“To fix all the vulnerabilities impacting your product(s), Atlassian recommends patching your instances to the latest version or one of the fixed versions for each product,” the company notes.

Related: Atlassian, Splunk Patch High-Severity Vulnerabilities

Related: Atlassian Patches Vulnerabilities in Bitbucket, Confluence, Jira

Related: Atlassian Patches Vulnerabilities in Bamboo, Bitbucket, Confluence, Crowd

Related: Details of Atlassian Confluence RCE Vulnerability Disclosed

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Joe Chen has become Chief Technology Officer at Trellix.

Usercentrics has named Pawan Hegde as COO and Elena Ignatova as CPTO.

SecureAuth has named Mark van Oppen as Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.