Critical Vulnerabilities In Atlassian Products: Analysis
ID: 96824fea-0d1a-5915-af9b-3453491695e8
STIX ID: report--96824fea-0d1a-5915-af9b-3453491695e8
Feed Name: Cyble Blog
CERT-In’s August 2024 bulletin documents multiple high-severity vulnerabilities in Atlassian products (Bamboo, Confluence, Crowd, Jira, Jira Service Management) and affected components (Bouncy Castle, Apache Tomcat). Notable issues include CVE-2024-37768 (Jira privilege escalation, CVSS 9.1), CVE-2024-21689 (Bamboo RCE, CVSS 7.6), CVE-2024-40859 (Confluence information disclosure, CVSS 7.5), and resource exhaustion in Bouncy Castle; the bulletin recommends immediate upgrades to patched versions, continuous monitoring, and other mitigation measures, citing prior active exploitation of a Confluence RCE and scanning of exposed instances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
