Atlassian has announced security updates that resolve six high-severity vulnerabilities in Bitbucket, Confluence, and Jira Service Management products.
The Bitbucket Data Center and Server updates resolve CVE-2024-21147, a high-severity flaw in the Java Runtime Environment (JRE) that could lead to unauthorized access to and tampering with critical data.
Oracle released patches for this bug as part of its July 2024 CPU and Atlassian included the patches in Bitbucket Data Center and Server versions 9.2.1, 8.19.10, and 8.9.20.
The Confluence Data Center and Server updates resolve four high-severity issues, including two in the Moment.js JavaScript date library that were publicly disclosed in 2022.
The two security defects, tracked as CVE-2022-24785 and CVE-2022-31129, are described as path traversal and ReDoS (Regular Expression Denial of Service) vulnerabilities that can be exploited without authentication.
The company also announced patches for CVE-2024-4367, an XSS bug that could allow authenticated attackers to execute arbitrary HTML or JavaScript code in a user’s browser, and for CVE-2024-29131, an Apache Commons Configuration flaw that could lead to DoS.
Confluence Data Center and Server versions 7.19.26, 8.0.0, 8.5.11, 8.9.3, and all versions greater than 9.0.0 contain fixes for these vulnerabilities.
Security updates released for Jira Service Management Data Center and Server resolve CVE-2024-7254, a Protobuf buffer overflow issue that could allow attackers to impact service availability.
Patches for this bug were included in Jira Service Management Data Center and Server versions 5.12.14, 5.17.4, and 10.1.1.
Although Atlassian makes no mention of any of these flaws being exploited in the wild, users are advised to update their deployments as soon as possible. Additional information can be found in Atlassian’s October 2024 security bulletin.
Related: Oracle Patches Over 200 Vulnerabilities With October 2024 CPU
Related: GitHub Patches Critical Vulnerability in Enterprise Server
Related: OpenSSL 1.1.1 Nears End of Life: Security Updates Only Until September 2023
Related: Npm Patches Vulnerability Allowing Access to User Files