Your review has been sent successfully

Atlassian Alert

2407
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

21 July, 2022

● High

2022-5046

All

Description:

Atlassian has released a security update to address several vulnerabilities in the following products:

  • Questions for Confluence app for
    • Confluence Server
    • Confluence Data Center
  • Bamboo Server and Data Center
  • Bitbucket Server and Data Center
  • Confluence Server and Data Center
  • Crowd Server and Data Center
  • Crucible
  • Fisheye
  • Jira Server and Data Center
  • Jira Service Management Server and Data Center
Threats:

Attacker could exploit these vulnerabilities by doing the following:

  • Authentication bypass
  • Cross-site scripting (XSS)
  • Cross-origin resource sharing (CORS) bypass
  • Unauthorized access
Best practice and Recommendations:

The CERT team encourages users to review Atlassian security advisory and apply the necessary updates:

Last updated at 21 July, 2022

Rate the content

rate-icon
up icon