Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Atlassian Patches Critical Vulnerabilities in Confluence, Crowd

Atlassian has released patches for 12 critical- and high-severity vulnerabilities in Bamboo, Bitbucket, Confluence, Crowd, and Jira.

Atlassian security updates

Atlassian this week announced the rollout of patches for 12 critical- and high-severity vulnerabilities in its Bamboo, Bitbucket, Confluence, Crowd, and Jira products.

The company released fixes for five critical-severity issues in Confluence Data Center and Server and Crowd Data Center and Server that were discovered in third-party dependencies used within the two products.

Updates released for Confluence Data Center and Server address two critical flaws in Apache Tomcat. Tracked as CVE-2024-50379 and CVE-2024-56337 (CVSS score of 9.8), the two issues could be exploited by unauthenticated attackers to achieve remote code execution (RCE), the company warns.

The two flaws were addressed in Crowd Data Center and Server as well, along with a third critical bug in Apache Tomcat, tracked as CVE-2024-52316 (CVSS score of 9.8). Also exploitable by unauthenticated attackers, the defect could lead to authentication bypass, Atlassian says.

The updates for Crowd also resolve a high-severity denial of service (DoS) vulnerability in ua-parser-js, which is tracked as CVE-2022-25927, Atlassian notes in its February 2025 security bulletin.

The company rolled out fixes for two high-severity DoS flaws in Bamboo Data Center and Server, affecting Protocol Buffers (CVE-2024-7254) and the XStream library (CVE-2024-47072), and for a high-severity RCE bug in Bitbucket Data Center and Server, impacting the Java SDK of Apache Avro (CVE-2024-47561).

Advertisement. Scroll to continue reading.

The DoS security defect in Protocol Buffers was also addressed in Jira Data Center and Server, Atlassian announced.

The company makes no mention of any of these vulnerabilities being exploited against its products, but urges customers to update their installations as soon as possible.

“To fix all the vulnerabilities impacting your product(s), Atlassian recommends patching your instances to the latest version or one of the fixed versions for each product,” the company notes.

Related: Atlassian, Splunk Patch High-Severity Vulnerabilities

Related: Atlassian Patches Vulnerabilities in Bitbucket, Confluence, Jira

Related: Atlassian Patches Vulnerabilities in Bamboo, Bitbucket, Confluence, Crowd

Related: Details of Atlassian Confluence RCE Vulnerability Disclosed

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn about Frontier Pace Governance: a practical approach to helping IT operations move at AI speed without sacrificing security, accountability, or operational discipline.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Rapid7 has named Rik Ferguson as VP of Security Intelligence.

Cytactic has appointed Tim Brown as CSO.

Scott Simkin has joined Vega as CMO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.