Analyze Recent Atlassian Vulnerabilities and Keep Your Infrastructure Protected
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-14589 | It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration rights to Bamboo or who hosts a website that a Bamboo administrator visits, is able to exploit this vulnerability to execute Java code of their choice on systems that run a vulnerable version of Bamboo. All versions of Bamboo before 6.1.6 (the fixed version for 6.1.x) and from 6.2.0 before 6.2.5 (the fixed version for 6.2.x) are affected by this vulnerability. NVD description · AI analysis pending | 9.6 | 2% |
| — | ||
| CVE-2019-11581 | Unauthenticated SSTI RCE in Atlassian Jira Server and Data Center Atlassian Jira Server and Data Center contain a server-side template injection (CWE-74) in the ContactAdministrators and SendBulkMail actions, rated critical at CVSS 9.8. The flaw is triggered by sending crafted, template-syntax input to these mail-related actions over the network; because the vulnerability requires no authentication or user interaction per the CVSS vector, any attacker who can reach the Jira web interface can trigger it. Successful exploitation yields unauthenticated remote code execution on the server hosting Jira, with high impact on confidentiality, integrity, and availability. Organizations running any Jira Server or Data Center release in the 4.4–7.6, 7.7–7.13, 8.0, 8.1, or 8.2 lines prior to the listed fixed versions are affected, and the exposure is concentrated among instances reachable from the internet. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-07 with a required action to apply vendor updates, and EPSS places it in the 100th percentile (~84.6% probability of exploitation within 30 days). Do: Apply the vendor updates per Atlassian/CISA instructions — upgrade to Jira 7.6.14, 7.13.5, 8.0.3, 8.1.2, or 8.2.3 (or later) as applicable, since this is a KEV item with a required patching action. As an interim mitigation, disable the 'Allow users to contact administrators' option in Jira's General Configuration to close the ContactAdministrators path and restrict SendBulkMail access, and limit exposure of the Jira web interface to the internet. Review access logs for requests hitting ContactAdministrators/SendBulkMail endpoints containing template injection payloads and hunt for signs of post-exploitation code execution on affected servers. | 9.8 | 85% | KEV |
| largetens of thousands of internet-exposed Jira Server/Data Center instances | |
| CVE-2019-15000 | The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed version fo The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed version for 6.0.x), from 6.1.0 before 6.1.8 (the fixed version for 6.1.x), from 6.2.0 before 6.2.6 (the fixed version for 6.2.x), from 6.3.0 before 6.3.5 (the fixed version for 6.3.x), from 6.4.0 before 6.4.3 (the fixed version for 6.4.x), and from 6.5.0 before 6.5.2 (the fixed version for 6.5.x) allows remote attackers who have permission to access a repository, if public access is enabled for a project or repository then attackers are able to exploit this issue anonymously, to read the contents of arbitrary files on the system and execute commands via injecting additional arguments into git commands. NVD description · AI analysis pending | 9.8 | 8% |
| — | ||
| CVE-2019-3394 | There was a local file disclosure vulnerability in Confluence Server and Confluence Data Center via page exporting. There was a local file disclosure vulnerability in Confluence Server and Confluence Data Center via page exporting. An attacker with permission to editing a page is able to exploit this issue to read arbitrary file on the server under /confluence/WEB-INF directory, which may contain configuration files used for integrating with other services, which could potentially leak credentials or other sensitive information such as LDAP credentials. The LDAP credential will be potentially leaked only if the Confluence server is configured to use LDAP as user repository. All versions of Confluence Server from 6.1.0 before 6.6.16 (the fixed version for 6.6.x), from 6.7.0 before 6.13.7 (the fixed version for 6.13.x), and from 6.14.0 before 6.15.8 (the fixed version for 6.15.x) are affected by this vulnerability. NVD description · AI analysis pending | 8.8 | 11% |
| — | ||
| CVE-2020-14179 | Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Inform Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from version 8.6.0 before 8.11.1. NVD description · AI analysis pending | 5.3 | 76% |
| — | ||
| CVE-2020-14181 | Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the / Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa endpoint. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, and from version 8.6.0 before 8.12.0. NVD description · AI analysis pending | 5.3 | 100% | PoC |
| — | |
| CVE-2020-29453 | The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check. NVD description · AI analysis pending | 5.3 | 24% |
| — | ||
| CVE-2020-36289 | Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the Q Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendererValue!Default.jspa endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 before 8.15.1. NVD description · AI analysis pending | 5.3 | 99% |
| — | ||
| CVE-2021-26084 | Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability CVE-2021-26084 is an OGNL injection vulnerability (CWE-917) in Atlassian Confluence Server and Data Center that may allow an unauthenticated attacker to execute arbitrary code. Any organization running Confluence Server or Data Center is potentially affected. It is significant because it is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware use, and EPSS assigns a 100.0% probability of exploitation within 30 days (100th percentile). Do: Apply updates to Confluence Server and Data Center per Atlassian's instructions, which is the required action in the CISA KEV listing. Prioritize remediation given confirmed in-the-wild exploitation and known ransomware use. | 9.8 | 100% | KEV ransomware PoC |
| — | |
| CVE-2021-26085 | Unauthenticated Arbitrary File Read in Atlassian Confluence Server CVE-2021-26085 is a pre-authorization arbitrary file read (CWE-425) in Atlassian Confluence Server, meaning an attacker needs no credentials to exploit it. It is triggered by sending crafted remote requests to Confluence's /s/ endpoint, which serves static resources, causing the server to expose restricted resources and files outside what an unauthenticated user should reach. Successful exploitation grants read access to arbitrary files on the Confluence host, which can expose configuration files, credentials, and other sensitive data. All unpatched Atlassian Confluence Server deployments are affected, particularly instances reachable from the internet. The flaw is listed in the CISA KEV catalog (added 2022-03-28) with known ransomware use, and its 99.9% EPSS probability of exploitation within 30 days indicates very widespread targeting, though no public PoC is cataloged. Do: Apply Atlassian's official updates for CVE-2021-26085 per the vendor's instructions as required by the CISA KEV listing, prioritizing internet-facing Confluence servers. Review access logs for suspicious requests to the /s/ endpoint and check for signs of follow-on compromise, since ransomware operators are known to exploit this flaw. Where possible, restrict direct internet exposure of Confluence until patching is complete. | 5.3 | 100% | KEV ransomware PoC |
| largeon the order of tens of thousands of internet-exposed Confluence Server instances, plus many more internal enterprise deployments | |
| CVE-2021-26086 | Path Traversal File Read in Atlassian Jira Server and Data Center Atlassian Jira Server and Data Center contain a path traversal flaw (CWE-22) in the /WEB-INF/web.xml endpoint that lets a remote attacker read particular files by sending crafted requests containing traversal sequences. Triggering requires only HTTP access to the affected endpoint on a vulnerable, self-hosted Jira instance; an attacker gains disclosure of specific files, an information-exposure condition that can aid further reconnaissance rather than full system compromise. Organizations running self-hosted Jira Server or Data Center are affected, while Atlassian Cloud is out of scope of this product listing. Exploitation is confirmed by CISA's inclusion of the bug in the Known Exploited Vulnerabilities catalog on 2024-11-12, and a top-percentile EPSS score of 100% indicates near-certain exploitation activity within 30 days; no public proof-of-concept is cataloged and ransomware association is listed as unknown. Do: Upgrade self-hosted Jira Server and Data Center to the fixed releases specified in Atlassian's advisory for CVE-2021-26086, since the provided data does not include exact version ranges. Audit internet-facing Jira instances for access to the /WEB-INF/web.xml endpoint and restrict or front-end Jira with access controls where patching must be delayed. Federal agencies must apply the vendor mitigation or discontinue use per the CISA KEV required action. | 5.3 | 100% | KEV PoC |
| mass≈100,000+ internet-exposed self-hosted Jira instances (public scan counts), with millions of users on self-hosted Jira overall | |
| CVE-2022-0540 | A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also affects Atlassian Jira Service Management Server and Data Center versions before 4.13.18, versions 4.14.0 and later before 4.20.6, and versions 4.21.0 and later before 4.22.0. NVD description · AI analysis pending | 9.8 | 88% |
| — | ||
| CVE-2022-26134 | Unauthenticated OGNL Injection RCE in Atlassian Confluence Server/Data Center Atlassian Confluence Server and Data Center contain an unauthenticated remote code execution flaw caused by improper neutralization of expression-language (OGNL) input (CWE-917): an attacker with network access to the application can submit a crafted request that is evaluated as an expression and executed by the server. Successful exploitation lets a remote, unauthenticated attacker run arbitrary code with the privileges of the Confluence process, without any credentials. All organizations running self-managed Confluence Server or Data Center are affected, particularly instances exposed to the internet; Confluence Cloud is not listed among the affected products. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-06-02 with ransomware use marked as known, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile). CVSS has not yet been scored in this data, but the KEV listing and known ransomware use make unpatched, internet-facing instances a top-priority patching target. Do: Immediately upgrade to the patched Confluence release specified in Atlassian's 2022-06-02 security advisory, and until patched follow the CISA required action to block all internet traffic to and from affected instances. Because in-the-wild exploitation and ransomware use are confirmed, also hunt for compromise indicators on both patched and unpatched hosts, such as webshells, unexpected child processes of the Confluence service, and unusual outbound connections. | 9.8 | 100% | KEV ransomware PoC ×2 |
| largetens of thousands of internet-exposed instances (public scan counts of roughly 60,000-90,000 Confluence Server/Data Center hosts around the June 2022… | |
| CVE-2022-26138 | Hard-coded Credentials in Atlassian Questions for Confluence App The Questions for Confluence app for Confluence Server and Data Center, when versions 2.7.34, 2.7.35, or 3.0.2 are installed, creates a user account named disabledsystemuser in the confluence-users group protected by a hard-coded password (CWE-798). Because the credential is embedded in the app, any remote, unauthenticated attacker who knows the password can log in to Confluence without a valid account. Successful exploitation grants access to all content that is accessible to the confluence-users group, which typically spans most of the instance's spaces and pages. Only Confluence Server and Data Center deployments that installed one of those app versions are affected, and the created account persists after installation. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-07-29 and carries a 98.2% EPSS score (100th percentile). Do: Upgrade the Questions for Confluence app to a fixed release per Atlassian's instructions, as required by the CISA KEV catalog. Check whether an account named disabledsystemuser exists in the confluence-users group; if present, delete it or change its hard-coded password, and review authentication logs for logins using that account. Prioritize internet-exposed Confluence Server and Data Center instances. | 9.8 | 98% | KEV |
| moderatelikely thousands of Confluence Server/Data Center instances (only those that installed the three named app versions) |
Full article1,004 words · extracted from recordedfuture.com · click to collapse
For years, software solutions built by Atlassian have found their way to nearly every organization's software stack. Tools such as JIRA, Confluence, Bamboo, and BitBucket are often seen playing a crucial role in various departments across enterprises.
From managing projects or handling organization-wide documentation, to hosting the very code of a product being developed by the organization, the constant reliance upon and amount of historical data held within these applications have turned them into a lucrative target for attackers, expanding the attack surface in the process.
Historical Atlassian Vulnerabilities
Traditionally, vulnerabilities within the Atlassian software stack have originated from different sources, including plugins backed by an extensive marketplace; yet, most have appeared as a result of its aging code stack.
Let's take a look at some of the most critical vulnerabilities and exposures (CVEs) seen in Atlassian software:
- CVE-2017-14589 (2017-12-13) - CVE Score 9.6 (Critical): An attacker who has restricted administration rights to Bamboo, or who hosts a website that a Bamboo administrator visits, can exploit this vulnerability to execute Java code of their choice on systems that run a vulnerable version of Bamboo.
- CVE-2019-3394 (2018-08-29) - CVE Score 8.8 (High): An attacker with permission to edit a page within Confluence Server and Confluence Data Center is able to exploit this vulnerability to read files on the server under the /confluence/WEB-INF directory, which usually contains configuration files which inturn can contain credentials used for integrating services with Confluence.
- CVE-2019-11581 (2019-08-09) - CVE Score 9.8 (Critical): A server-side template injection vulnerability in Jira Server and Data Center inside the ContactAdministrators and the SendBulkMail areas may allow remote code execution.
- CVE-2019-15000 (2019-09-19) - CVE Score 9.8 (Critical): If public access is enabled for a project or repository, attackers can exploit this issue without any need for authentication while being able to read file contents or execute commands by injecting additional arguments via git commands.
As mentioned, plugins from various software vendors have been a constant source of vulnerabilities. Often, 3rd-party plugin developers are to blame for the incorrect implementation of APIs and credential stores, but, at times, vulnerabilities can be caused by plugins developed by first-party developers as well.
Recent Critical Atlassian CVEs
Let's take a look at some of the recent critical vulnerabilities that have affected Atlassian tools.
JIRA, being one of the most popular tools used for software development and IT help desks, has seen quite a few vulnerabilities in the recent past. For example, a recent vulnerability CVE-2020-14179 allowed remote unauthenticated users to view custom fields and custom SLA names by querying the secure /secure/QueryComponent!Default.jspa endpoint.
Similar vulnerabilities have allowed unauthenticated users to enumerate users in a JIRA server (CVE-2020-14181 / CVE-2020-36289) by accessing the /secure/ViewUserHover.jspa endpoint.
Other vulnerabilities allowed threat actors to read of certain system-level files, potentially exposing further information about the JIRA configuration (CVE-2020-29453 / CVE-2021-26086).
For example, an attacker could make GET requests to the /s/cfx/_/;/.
Wherein the could be,
- WEB-INF/web.xml
- WEB-INF/decorators.xml
- WEB-INF/classes/seraph-config.xml
- META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties
- META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.xml
- META-INF/maven/com.atlassian.jira/atlassian-jira-webapp/pom.xml
- META-INF/maven/com.atlassian.jira/atlassian-jira-webapp/pom.properties
and JIRA would return the contents of these files, exposing certain configurations and other server information stored within them.
JIRA has also been a victim of critical vulnerabilities such as complete authentication bypasses by using specially crafted HTTP requests, scoring a 9.8 (Critical) score on the CVE Scale (CVE-2022-0540). This vulnerability can be exploited through the use of specific plugins, such as Mobile Plugin for Jira, Insight - Asset Management, allowing attackers to execute certain scripts on the server via the job scheduler configuration at the URL: /secure/WBSGanttManageScheduleJobAction.jspa.
Looking at another widely used Atlassian tool, Confluence has experienced critical vulnerabilities such as allowing remote attackers to execute code on a Confluence Server (CVE-2021-26084 / CVE-2022-26134) via injection attacks, while other vulnerabilities allowed attackers to view restricted resources on a Confluence Server (CVE-2021-26085), wherein the payload:
${(#[email protected]@toString(@java.lang.Runtime@getRuntime().exec("id").getInputStream(),"utf-8")).(@com.opensymphony.webwork.ServletActionContext@getResponse().setHeader("X-Cmd-Response",#a))} ${(#[email protected]@toString(@java.lang.Runtime@getRuntime().exec("id").getInputStream(),"utf-8")).(@com.opensymphony.webwork.ServletActionContext@getResponse().setHeader("X-Cmd-Response",#a))}was sent as an HTTP response header that executed the command on the server hosting the confluence instance.
Beyond these application-level vulnerabilities, popular first-party plugins have also seen critical vulnerabilities. Take, for example CVE-2022-26138, which was caused by a widely used plugin named “Questions for Confluence”. Developed by Atlassian, the plugin provides a discussion forum-like experience within Confluence by allowing users to ask questions and interact with each other. In short, the plugin created a user within the system named “disabledsystemuser”, with a hardcoded password, which an unauthenticated attacker with access to these credentials could simply exploit to log in to the Confluence server.
Looking into vulnerabilities within the software stack itself, CVE-2022-26134 is a good example of an Atlassian case in point wherein the vulnerability existed right within the application. Using an Object-Graph Navigation Language (OGNL) injection, an unauthenticated attacker could execute arbitrary code on a Confluence Server. This vulnerability allowed any code or /command to be executed on a vulnerable server hosting Confluence, allowing the compromised server to be used for malware distribution, cryptocurrency mining, and ultimately any other security threat.
Identifying Vulnerable Atlassian-based Vulnerabilities on Your Infrastructure
The process of identifying vulnerabilities within an organization's infrastructure is seen as a never-ending, complex task. However, the process of scanning infrastructure has been simplified over the years with the introduction of various open-source and free-to-use tools, yet knowing “what to scan” and “what vulnerabilities to scan for” remains a major challenge.
With frequent new CVE announcements, keeping one's scanning tools up-to-date with the knowledge of these new CVEs is seen as one of the biggest hurdles for security researchers.
Using the Recorded Future Attack Surface Intelligence module ensures complete end-to-end automation of your organization's security needs:
- Automated scans of your infrastructure without missing a single host during the scanning process
- Your hosts are also scanned for the latest CVEs and known vulnerabilities
As shown below, Recorded Future Attack Surface Intelligence can seamlessly identify any Atlassian infrastructure in your environment and alert you to its potential vulnerabilities — even the latest CVEs.
Here’s a brief overview of the 23 most critical Atlassian CVEs detected by our engine, at the time of this writing:
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.recordedfuture.com/blog/analyze-recent-atlassian-vulnerabilities