Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Atlassian Patches Critical Vulnerabilities in Confluence, Crowd

Atlassian has released patches for 12 critical- and high-severity vulnerabilities in Bamboo, Bitbucket, Confluence, Crowd, and Jira.

Atlassian security updates

Atlassian this week announced the rollout of patches for 12 critical- and high-severity vulnerabilities in its Bamboo, Bitbucket, Confluence, Crowd, and Jira products.

The company released fixes for five critical-severity issues in Confluence Data Center and Server and Crowd Data Center and Server that were discovered in third-party dependencies used within the two products.

Updates released for Confluence Data Center and Server address two critical flaws in Apache Tomcat. Tracked as CVE-2024-50379 and CVE-2024-56337 (CVSS score of 9.8), the two issues could be exploited by unauthenticated attackers to achieve remote code execution (RCE), the company warns.

The two flaws were addressed in Crowd Data Center and Server as well, along with a third critical bug in Apache Tomcat, tracked as CVE-2024-52316 (CVSS score of 9.8). Also exploitable by unauthenticated attackers, the defect could lead to authentication bypass, Atlassian says.

The updates for Crowd also resolve a high-severity denial of service (DoS) vulnerability in ua-parser-js, which is tracked as CVE-2022-25927, Atlassian notes in its February 2025 security bulletin.

The company rolled out fixes for two high-severity DoS flaws in Bamboo Data Center and Server, affecting Protocol Buffers (CVE-2024-7254) and the XStream library (CVE-2024-47072), and for a high-severity RCE bug in Bitbucket Data Center and Server, impacting the Java SDK of Apache Avro (CVE-2024-47561).

The DoS security defect in Protocol Buffers was also addressed in Jira Data Center and Server, Atlassian announced.

The company makes no mention of any of these vulnerabilities being exploited against its products, but urges customers to update their installations as soon as possible.

Advertisement. Scroll to continue reading.

“To fix all the vulnerabilities impacting your product(s), Atlassian recommends patching your instances to the latest version or one of the fixed versions for each product,” the company notes.

Related: Atlassian, Splunk Patch High-Severity Vulnerabilities

Related: Atlassian Patches Vulnerabilities in Bitbucket, Confluence, Jira

Related: Atlassian Patches Vulnerabilities in Bamboo, Bitbucket, Confluence, Crowd

Related: Details of Atlassian Confluence RCE Vulnerability Disclosed

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this event as we dive into threat hunting tools and frameworks, and explore value of threat intelligence data in the defender’s security stack.

Register

Learn how integrating BAS and Automated Penetration Testing empowers security teams to quickly identify and validate threats, enabling prompt response and remediation.

Register

People on the Move

SplxAI, a startup focused on securing AI agents, has announced new CISO Sandy Dunn.

Phillip Miller is joining tax preparation giant H&R Block as VP and CISO.

Linx Security has appointed Sarit Reiner Frumkes as Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.