Atlassian publikuje poprawki do swoich produktów 03/26 (P26-100)

cert.pse-online.pl 1 tydzień temu

17 marca 2026 r. firma Atlassian opublikowała ostrzeżenie dotyczące bezpieczeństwa w celu usunięcia luk w zabezpieczeniach następujących produktów:

  • Bamboo Data Center i Server – wiele wersji
  • Bitbucket Data Center i Server – wersja 9.4.16 (LTS), wersje od 10.1.1 do 10.1.4
  • Confluence Data Center i Server – wiele wersji
  • Crowd Data Center i Server – wiele wersji
  • Fisheye/Crucible – wersja 4.8.16, wersje od 4.9.0 do 4.9.7
  • Jira Data Center i Server – wiele wersji
  • Jira Service Management Data Center i Server – wiele wersji
ProduktPodatna wersjaPatchLink/OpisCVE IDCVSS
Bamboo Data Center and Server12.1.0 to 12.1.2 (LTS) 12.0.0 to 12.0.2 11.0.0 to 11.0.8 10.2.0 to 10.2.15 (LTS) 10.1.0 to 10.1.1 10.0.0 to 10.0.3 9.6.1 to 9.6.23 (LTS)12.1.3 (LTS) zalecane tylko Data Center 10.2.16 (LTS) tylko Data Center 9.6.24 (LTS) tylko Data CenterRCE (Remote Code Execution) in Bamboo Data CenterCVE-2026-215708.6 Wysoka
Missing XML Validation vulnerability in Apache Struts Dependency in Bamboo Data CenterCVE-2025-684938.1 Wysoka
DoS (Denial of Service) Apache Struts Dependency in Bamboo Data CenterCVE-2025-647757.1 Wysoka
Bitbucket Data Center and Server10.1.1 to 10.1.4 9.4.16 (LTS)10.2.0 do 10.2.1 (LTS) zalecane tylko Data Center 10.1.5 tylko Data Center 9.4.17 do 9.4.18 (LTS) tylko Data CenterDoS (Denial of Service) semver Dependency in Bitbucket Data Center and ServerCVE-2022-258837.5 Wysoka
Confluence Data Center and Server10.2.0 to 10.2.6 (LTS) 10.1.0 to 10.1.2 9.5.1 to 9.5.4 9.2.5 to 9.2.14 (LTS) 9.0.110.2.7 (LTS) tylko Data Center 9.2.15 do 9.2.17 (LTS) tylko Data Center 9.0.2 do 9.0.3 tylko Data CenterOS Command Injection glob Dependency in Confluence Data Center and ServerCVE-2025-647567.5 Wysoka
Crowd Data Center and Server7.1.0 to 7.1.3 7.0.0 to 7.0.2 6.3.0 to 6.3.4 6.2.2 to 6.2.6 6.1.3 to 6.1.7 6.0.0 to 6.0.10 5.3.1 to 5.3.87.1.5 zalecane tylko Data Center 6.3.5 tylko Data CenterDOM-based XSS react-router-dom Dependency in Crowd Data CenterCVE-2026-218848.2 Wysoka
DOM-based XSS @remix-run/router Dependency in Crowd Data CenterCVE-2026-220298 Wysoka
DoS (Denial of Service) axios Dependency in Crowd Data CenterCVE-2026-256397.5 Wysoka
Fisheye/Crucible4.9.0 to 4.9.7 4.8.164.9.8 zalecaneDoS (Denial of Service) com.nimbusds:nimbus-jose-jwt Dependency in Crucible Data Center and ServerCVE-2023-524287.5 Wysoka
Jira Data Center and Server11.3.0 to 11.3.2 (LTS) 11.2.0 to 11.2.1 11.1.0 to 11.1.1 11.0.0 to 11.0.1 10.7.1 to 10.7.4 10.6.0 to 10.6.1 10.5.0 to 10.5.1 10.4.0 to 10.4.1 10.3.0 to 10.3.17 (LTS) 10.2.0 to 10.2.1 10.1.1 to 10.1.2 10.0.0 to 10.0.1 9.17.0 to 9.17.5 9.16.0 to 9.16.1 9.15.211.3.3 (LTS) zalecane tylko Data Center 10.3.18 (LTS) tylko Data CenterPath Traversal node-tar Dependency in Jira Software Data CenterCVE-2026-239508.8 Wysoka
File Inclusion node-tar Dependency in Jira Software Data CenterCVE-2026-237458.2 Wysoka
File Inclusion node-tar Dependency in Jira Software Data CenterCVE-2026-248428.2 Wysoka
DoS (Denial of Service) ua-parser-js Dependency in Jira Software Data CenterCVE-2022-259277.5 Wysoka
DoS (Denial of Service) semver Dependency in Jira Software Data Center and ServerCVE-2022-258837.5 Wysoka
DoS (Denial of Service) glob-parent Dependency in Jira Software Data CenterCVE-2020-284697.5 Wysoka
Jira Service Management Data Center and Server11.3.0 to 11.3.2 (LTS) 11.2.0 to 11.2.1 11.1.0 to 11.1.1 11.0.0 to 11.0.1 10.7.1 to 10.7.4 10.6.0 to 10.6.1 10.5.0 to 10.5.1 10.4.0 to 10.4.1 10.3.0 to 10.3.17 (LTS) 10.2.0 to 10.2.1 10.1.1 to 10.1.2 10.0.0 to 10.0.1 5.17.0 to 5.17.5 5.16.0 to 5.16.1 5.15.2 5.12.29 to 5.12.33 (LTS)11.3.3 (LTS) zalecane tylko Data Center 10.3.18 (LTS) tylko Data CenterPath Traversal node-tar Dependency in Jira Service Management Data CenterCVE-2026-239508.8 Wysoka
File Inclusion node-tar Dependency in Jira Service Management Data CenterCVE-2026-237458.2 Wysoka
File Inclusion node-tar Dependency in Jira Service Management Data CenterCVE-2026-248428.2 Wysoka
DoS (Denial of Service) net.minidev:json-smart Dependency in Jira Service Management Data Center and ServerCVE-2024-576997.5 Wysoka
DoS (Denial of Service) ua-parser-js Dependency in Jira Service Management Data Center and ServerCVE-2022-259277.5 Wysoka
DoS (Denial of Service) glob-parent Dependency in Jira Service Management Data CenterCVE-2020-284697.5 Wysoka
Idź do oryginalnego materiału