Menu
Atlassian fixes critical vulnerability in development collaboration products

Atlassian fixes critical vulnerability in development collaboration products

The flaw can be exploited to execute malicious Java code on servers

A critical vulnerability in popular software development collaboration products by Atlassian allows attackers to compromise servers.

The vulnerability affects Atlassian Confluence, a wiki-like collaboration platform for software development teams; Bamboo, a software build and testing platform; FishEye, a code-tracking system for centralizing different repositories; and Crucible, a collaborative peer code review framework.

Attackers can exploit the vulnerability to execute arbitrary Java code on systems that use the affected frameworks, as long as they can access their Web interfaces, the company said in security advisories published Wednesday. To exploit Confluence, the attacker also needs to have access to an account on the platform.

The impact of the vulnerability depends on what data is stored on those systems and what the malicious Java code is designed to do.

Atlassian released patches for all of the affected products. Confluence users are advised to apply the webwork-2.1.5-atlassian-3.jar patch, Bamboo users should apply the freemarker-2.3.16-atlassian-34.jar patch, while FishEye and Crucible users should upgrade to the newly released 3.5.5 or 3.6.2 versions.

If the affected products are not directly accessible from the Internet or other untrusted networks, the risk of compromise is reduced because the attacker would first have to gain access to the same network as the servers hosting them. Companies whose installations need to be accessible from the Internet can block requests in their firewalls that match specific regular expressions released by Atlassian.

Atlassian has over 35,000 customers worldwide, including large Internet and software development companies like Facebook, Twitter, Hulu, eBay, LinkedIn, Twitter, Netflix, Adobe Systems, Microsoft and Cisco Systems.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags patch managementatlassianpatchesExploits / vulnerabilities

Featured

Slideshows

The making of an MSSP: a blueprint for growth in NZ

The making of an MSSP: a blueprint for growth in NZ

Partners are actively building out security practices and services to match, yet remain challenged by a lack of guidance in the market. This exclusive Reseller News Roundtable - in association with Sophos - assessed the making of an MSSP, outlining the blueprint for growth and how partners can differentiate in New Zealand.

The making of an MSSP: a blueprint for growth in NZ
Reseller News Platinum Club celebrates leading partners in 2018

Reseller News Platinum Club celebrates leading partners in 2018

The leading players of the New Zealand channel came together to celebrate a year of achievement at the inaugural Reseller News Platinum Club lunch in Auckland. Following the Reseller News Innovation Awards, Platinum Club provides a platform to showcase the top performing partners and start-ups of the past 12 months, with more than ​​50 organisations in the spotlight.​​​

Reseller News Platinum Club celebrates leading partners in 2018
Meet the top performing HP partners in NZ

Meet the top performing HP partners in NZ

HP has honoured its leading partners in New Zealand during 2018, following 12 months of growth through the local channel. Unveiled during the fourth running of the ceremony in Auckland, the awards recognise and celebrate excellence, growth, consistency and engagement of standout Kiwi partners.

Meet the top performing HP partners in NZ
Show Comments