Description

Atlassian has released a security bulletin detailing nine high-severity vulnerabilities affecting its Bamboo, Confluence, Crowd, and Jira products. Bamboo received patches for two critical vulnerabilities CVE-2024-21689 and CVE-2024-29857. The first allows authenticated remote code execution, while the second, a denial-of-service issue, can be exploited without authentication. Atlassian's Confluence product was impacted by two critical vulnerabilities: CVE-2024-34750 and CVE-2024-21690. The first is a denial-of-service vulnerability in Apache Tomcat, and the second is a reflected XSS and CSRF issue that could allow attackers to execute arbitrary code in a victim's browser. Atlassian's Crowd product was affected by three critical vulnerabilities CVE-2024-22259, CVE-2024-22243, and CVE-2024-22262. These vulnerabilities, all related to the Spring Framework, could allow attackers to bypass authentication or execute arbitrary code. Jira was also impacted by a high-severity vulnerability CVE-2024-34750. CVE-2024-34750 is a vulnerability in Apache Tomcat that could lead to denial-of-service attacks. This means that an attacker could exploit the vulnerability to overload the system and make it unavailable to legitimate users. Atlassian has released patches for all of these vulnerabilities, and users are advised to update their installations as soon as possible. While there is no evidence of these vulnerabilities being actively exploited, it is important to apply the patches to protect against potential future attacks.