Menu
Atlassian fixes critical vulnerability in development collaboration products

Atlassian fixes critical vulnerability in development collaboration products

The flaw can be exploited to execute malicious Java code on servers

A critical vulnerability in popular software development collaboration products by Atlassian allows attackers to compromise servers.

The vulnerability affects Atlassian Confluence, a wiki-like collaboration platform for software development teams; Bamboo, a software build and testing platform; FishEye, a code-tracking system for centralizing different repositories; and Crucible, a collaborative peer code review framework.

Attackers can exploit the vulnerability to execute arbitrary Java code on systems that use the affected frameworks, as long as they can access their Web interfaces, the company said in security advisories published Wednesday. To exploit Confluence, the attacker also needs to have access to an account on the platform.

The impact of the vulnerability depends on what data is stored on those systems and what the malicious Java code is designed to do.

Atlassian released patches for all of the affected products. Confluence users are advised to apply the webwork-2.1.5-atlassian-3.jar patch, Bamboo users should apply the freemarker-2.3.16-atlassian-34.jar patch, while FishEye and Crucible users should upgrade to the newly released 3.5.5 or 3.6.2 versions.

If the affected products are not directly accessible from the Internet or other untrusted networks, the risk of compromise is reduced because the attacker would first have to gain access to the same network as the servers hosting them. Companies whose installations need to be accessible from the Internet can block requests in their firewalls that match specific regular expressions released by Atlassian.

Atlassian has over 35,000 customers worldwide, including large Internet and software development companies like Facebook, Twitter, Hulu, eBay, LinkedIn, Twitter, Netflix, Adobe Systems, Microsoft and Cisco Systems.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags securitypatch managementatlassianpatchesExploits / vulnerabilities

Featured

Slideshows

Meet the leading female front runners of the Kiwi channel

Meet the leading female front runners of the Kiwi channel

Reseller News honoured the leading female front runners of the New Zealand channel at the 2018 Women in ICT Awards (WIICTA) in Auckland. The awards honoured standout individuals across seven categories, spanning Entrepreneur; Innovation; Rising Star; Shining Star; Community; Technical and Achievement.

Meet the leading female front runners of the Kiwi channel
Meet the top performing customer-centric Microsoft channel partners

Meet the top performing customer-centric Microsoft channel partners

Microsoft honoured leading partners across the channel following a year of customer innovation and market growth in New Zealand. The 2018 Microsoft Partner Awards recognised excellence within the context of the end-user, spanning a host of emerging and established providers.

Meet the top performing customer-centric Microsoft channel partners
Reseller News launches new-look Awards at 2018 Judges’ Lunch

Reseller News launches new-look Awards at 2018 Judges’ Lunch

Introducing the Reseller News Innovation Awards, launched to the channel at the 2018 Judges’ Lunch in Auckland. With more than 70 judges now part of the voting panel, the new-look awards will reflect the changing dynamics of the channel, recognising excellence across customer value and innovation - spanning start-ups, partners, distributors and vendors.

Reseller News launches new-look Awards at 2018 Judges’ Lunch
Show Comments