Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Atlassian Patches Vulnerabilities in Bitbucket, Confluence, Jira

Atlassian has released patches for high-severity vulnerabilities in Bitbucket, Confluence, and Jira Service Management.

Atlassian has announced security updates that resolve six high-severity vulnerabilities in Bitbucket, Confluence, and Jira Service Management products.

The Bitbucket Data Center and Server updates resolve CVE-2024-21147, a high-severity flaw in the Java Runtime Environment (JRE) that could lead to unauthorized access to and tampering with critical data.

Oracle released patches for this bug as part of its July 2024 CPU and Atlassian included the patches in Bitbucket Data Center and Server versions 9.2.1, 8.19.10, and 8.9.20.

The Confluence Data Center and Server updates resolve four high-severity issues, including two in the Moment.js JavaScript date library that were publicly disclosed in 2022.

The two security defects, tracked as CVE-2022-24785 and CVE-2022-31129, are described as path traversal and ReDoS (Regular Expression Denial of Service) vulnerabilities that can be exploited without authentication.

The company also announced patches for CVE-2024-4367, an XSS bug that could allow authenticated attackers to execute arbitrary HTML or JavaScript code in a user’s browser, and for CVE-2024-29131, an Apache Commons Configuration flaw that could lead to DoS.

Advertisement. Scroll to continue reading.

Confluence Data Center and Server versions 7.19.26, 8.0.0, 8.5.11, 8.9.3, and all versions greater than 9.0.0 contain fixes for these vulnerabilities.

Security updates released for Jira Service Management Data Center and Server resolve CVE-2024-7254, a Protobuf buffer overflow issue that could allow attackers to impact service availability.

Patches for this bug were included in Jira Service Management Data Center and Server versions 5.12.14, 5.17.4, and 10.1.1.

Although Atlassian makes no mention of any of these flaws being exploited in the wild, users are advised to update their deployments as soon as possible. Additional information can be found in Atlassian’s October 2024 security bulletin.

Related: Oracle Patches Over 200 Vulnerabilities With October 2024 CPU

Related: GitHub Patches Critical Vulnerability in Enterprise Server

Related: OpenSSL 1.1.1 Nears End of Life: Security Updates Only Until September 2023

Related: Npm Patches Vulnerability Allowing Access to User Files

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.

Ruben D. Chacon has joined ADM as Vice President and Global CISO.

GDIT has appointed retired Maj. Gen. Ryan Heritage as Vice President, Full-Spectrum Cyber.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.