Atlassian fixed six high
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-25647 | The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks. NVD description · AI analysis pending | 7.5 | 12% |
| — | ||
| CVE-2024-21685 | This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data Center. This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data Center. This Information Disclosure vulnerability, with a CVSS Score of 7.4, allows an unauthenticated attacker to view sensitive information via an Information Disclosure vulnerability which has high impact to confidentiality, no impact to integrity, no impact to availability, and requires user interaction. Atlassian recommends that Jira Core Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Jira Core Data Center 9.4: Upgrade to a release greater than or equal to 9.4.21 Jira Core Data Center 9.12: Upgrade to a release greater than or equal to 9.12.8 Jira Core Data Center 9.16: Upgrade to a release greater than or equal to 9.16.0 See the release notes. You can download the latest version of Jira Core Data Center from the download center. This vulnerability was found internally. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2024-22243 | Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks. NVD description · AI analysis pending | 8.1 | 4% | — | — | ||
| CVE-2024-22257 | In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter. NVD description · AI analysis pending | 8.2 | <1% | — | — | ||
| CVE-2024-22259 | Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks. This is the same as CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input. NVD description · AI analysis pending | 8.1 | 3% |
| — | ||
| CVE-2024-22262 | Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks. This is the same as CVE-2024-22259 https://spring.io/security/cve-2024-22259 and CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input. NVD description · AI analysis pending | 8.1 | 1% | — | — | ||
| CVE-2024-29131 +1 in the same advisory: …29133 | Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue. NVD description · AI analysis pending | 7.3 group max | 2% |
| — |
Full article394 words · extracted from securityaffairs.com · click to collapse

Australian software company Atlassian addressed multiple high-severity vulnerabilities in its Confluence, Crucible, and Jira solutions.
Atlassian June 2024 Security Bulletin addressed nine high-severity vulnerabilities in Confluence, Crucible, and Jira products.
The most severe issue addressed by the company is an improper authorization org.springframework.security:spring-security-core dependency in Confluence Data Center and Server. The flaw tracked as CVE-2024-22257 received a CVSS score of 8.2.
The Confluence Data Center and Server update resolved other five SSRF (Server-Side Request Forgery) and DoS vulnerabilities. Below is the list of the addressed flaws:
Confluence Data Center and Server versions 8.9.3, 8.5.11 (LTS), and 7.19.24 (LTS) addressed these vulnerabilities.
Atlassian also fixed a DoS vulnerability, tracked as CVE-2022-25647, in the Fisheye/Crucible with the release of version 4.8.15.
The software firm also fixed the following vulnerabilities in the Jira Data Center and Server:
| Jira Data Center and Server | 9.12.0 to 9.12.7 (LTS)9.4.0 to 9.4.20 (LTS) | 9.16.0 to 9.16.1 Data Center Only9.12.8 to 9.12.10 (LTS) recommended9.4.21 to 9.4.23 (LTS) | Information Disclosure in Jira Core Data Center | CVE-2024-21685 | 7.4 High |
| Jira Service Management Data Center and Server | 5.15.25.12.0 to 5.12.7 (LTS)5.4.0 to 5.4.20 (LTS) | 5.16.0 to 5.16.1 Data Center Only5.12.8 to 5.12.10 (LTS) recommended5.4.21 to 5.4.23 (LTS) | Information Disclosure in Jira Service Management Data Center and Server | CVE-2024-21685 | 7.4 High |
The company is not aware of attacks in the wild exploiting the vulnerabilities fixed in the June 2024 Security Bulletin.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, China)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/164743/security/atlassian-confluence-crucible-jira-flaws.html