Atlassian this week announced the rollout of patches for 12 critical- and high-severity vulnerabilities in its Bamboo, Bitbucket, Confluence, Crowd, and Jira products.
The company released fixes for five critical-severity issues in Confluence Data Center and Server and Crowd Data Center and Server that were discovered in third-party dependencies used within the two products.
Updates released for Confluence Data Center and Server address two critical flaws in Apache Tomcat. Tracked as CVE-2024-50379 and CVE-2024-56337 (CVSS score of 9.8), the two issues could be exploited by unauthenticated attackers to achieve remote code execution (RCE), the company warns.
The two flaws were addressed in Crowd Data Center and Server as well, along with a third critical bug in Apache Tomcat, tracked as CVE-2024-52316 (CVSS score of 9.8). Also exploitable by unauthenticated attackers, the defect could lead to authentication bypass, Atlassian says.
The updates for Crowd also resolve a high-severity denial of service (DoS) vulnerability in ua-parser-js, which is tracked as CVE-2022-25927, Atlassian notes in its February 2025 security bulletin.
The company rolled out fixes for two high-severity DoS flaws in Bamboo Data Center and Server, affecting Protocol Buffers (CVE-2024-7254) and the XStream library (CVE-2024-47072), and for a high-severity RCE bug in Bitbucket Data Center and Server, impacting the Java SDK of Apache Avro (CVE-2024-47561).
The DoS security defect in Protocol Buffers was also addressed in Jira Data Center and Server, Atlassian announced.
The company makes no mention of any of these vulnerabilities being exploited against its products, but urges customers to update their installations as soon as possible.
“To fix all the vulnerabilities impacting your product(s), Atlassian recommends patching your instances to the latest version or one of the fixed versions for each product,” the company notes.
Related: Atlassian, Splunk Patch High-Severity Vulnerabilities
Related: Atlassian Patches Vulnerabilities in Bitbucket, Confluence, Jira
Related: Atlassian Patches Vulnerabilities in Bamboo, Bitbucket, Confluence, Crowd
Related: Details of Atlassian Confluence RCE Vulnerability Disclosed
