Atlassian publikuje poprawki do swoich produktów 07/25 (P25-228)

cert.pse-online.pl 12 godzin temu

15 lipca 2025 r. firma Atlassian opublikowała ostrzeżenie dotyczące bezpieczeństwa w celu usunięcia luk w następujących produktach:

  • Bamboo Data Center i Server – wiele wersji
  • Bitbucket Data Center i Server – wiele wersji
  • Confluence Data Center i Server – wiele wersji
  • Crowd Data Center i Server – wiele wersji
  • Jira Data Center i Server – wiele wersji
  • Jira Service Management Data Center i Server – wiele wersji
ProduktWersja PodatnaPatchOpis/LinkCVE IDCVSS Krytyczność
Bamboo Data Center and Server11.0.0 do 11.0.2 10.2.0 do 10.2.5 (LTS) 10.1.0 do 10.1.1 10.0.0 do 10.0.3 9.6.0 do 9.6.14 (LTS) 9.5.0 do 9.5.4 9.4.0 do 9.4.4 9.3.0 do 9.3.611.0.3 Tylko Data Center 10.2.6 (LTS) rekomendowany Tylko Data Center 9.6.15 (LTS) Tylko Data CenterRCE (Remote Code Execution) Third-Party Dependency in Bamboo Data Center and ServerCVE-2025-487348.8 Wysoka
Third-Party Dependency in Bamboo Data Center and ServerCVE-2025-491468.2 Wysoka
DoS (Denial of Service) Third-Party Dependency in Bamboo Data Center and ServerCVE-2025-489767.5 Wysoka
Third-Party Dependency in Bamboo Data Center and ServerCVE-2025-278207.5 Wysoka
Third-Party Dependency in Bamboo Data Center and ServerCVE-2024-130097.2 Wysoka
Bitbucket Data Center and Server9.6.0 do 9.6.3 9.4.0 do 9.4.7 (LTS) 8.19.0 do 8.19.19 (LTS)9.6.4 Tylko Data Center 9.4.8 (LTS) rekomendowany Tylko Data Center 8.19.20 (LTS) Tylko Data CenterImproper Authorization org.apache.tomcat.embed:tomcat-embed-core Dependency in Bitbucket Data Center and ServerCVE-2025-467017.3 Wysoka
Confluence Data Center and Server9.5.1 9.4.0 do 9.4.1 9.2.4 do 9.2.5 (LTS)9.5.2 Tylko Data Center 9.2.6 (LTS) rekomendowany Tylko Data CenterMITM (Man-in-the-Middle) org.apache.httpcomponents.client5:httpclient5 Dependency in Confluence Data Center and ServerCVE-2025-278207.5 Wysoka
Crowd Data Center and Server5.2.0 do 5.2.10 5.1.4 do 5.1.13 5.0.7 do 5.0.115.2.11 rekomendowanyRCE (Remote Code Execution) com.typesafe.akka:akka-actor_2.11 Dependency in Crowd Data Center and ServerCVE-2017-10000348.1 Wysoka
Jira Data Center and Server10.7.1 10.6.0 do 10.6.1 10.5.0 do 10.5.1 10.4.0 do 10.4.1 10.3.0 do 10.3.7 (LTS) 10.2.0 do 10.2.1 10.1.1 do 10.1.2 10.0.0 do 10.0.1 9.17.0 do 9.17.5 9.12.0 do 9.12.24 (LTS) 9.4.0 do 9.4.30 (LTS)10.7.2 Tylko Data Center 10.3.8 (LTS) rekomendowany Tylko Data Center 9.12.25 (LTS)XSS (Cross Site Scripting) DOMPurify Dependency in Jira Core Data Center and ServerCVE-2024-458018.3 Wysoka
MITM (Man-in-the-Middle) org.apache.httpcomponents.client5:httpclient5 Dependency in Jira Software Data Center and ServerCVE-2025-278207.5 Wysoka
DoS (Denial of Service) org.apache.tomcat:tomcat-catalina Dependency in Jira Software Data Center and ServerCVE-2025-489887.5 Wysoka
BASM (Broken Authentication and Session Management) org.apache.tomcat:tomcat-catalina Dependency in Jira Software Data Center and ServerCVE-2025-491257.5 Wysoka
BASM (Broken Authentication & Session Management) org.springframework.security:spring-security-crypto Dependency in Jira Software Data Center and ServerCVE-2025-222287.4 Wysoka
Improper Authorization org.apache.tomcat:tomcat-catalina Dependency in Jira Software Data Center and ServerCVE-2025-467017.3 Wysoka
Jira Service Management Data Center and Server10.7.1 10.6.0 do 10.6.1 10.5.0 do 10.5.1 10.4.0 do 10.4.1 10.3.0 do 10.3.7 (LTS) 10.2.0 do 10.2.1 10.1.1 do 10.1.2 10.0.0 do 10.0.1 5.17.0 do 5.17.5 5.12.0 do 5.12.24 (LTS) 5.4.0 do 5.4.30 (LTS)10.7.2 Tylko Data Center 10.3.8 (LTS) rekomendowany Tylko Data Center 5.12.25 (LTS)XSS (Cross Site Scripting) DOMPurify Dependency in Jira Service Management Data Center and ServerCVE-2024-458018.3 Wysoka
MITM (Man-in-the-Middle) org.apache.httpcomponents.client5:httpclient5 Dependency in Jira Service Management Data Center and ServerCVE-2025-278207.5 Wysoka
BASM (Broken Authentication and Session Management) org.apache.tomcat:tomcat-catalina Dependency in Jira Service Management Data Center and ServerCVE-2025-491257.5 Wysoka
DoS (Denial of Service) org.apache.tomcat:tomcat-catalina Dependency in Jira Service Management Data Center and ServerCVE-2025-489887.5 Wysoka
BASM (Broken Authentication & Session Management) org.springframework.security:spring-security-crypto Dependency in Jira Service Management Data Center and ServerCVE-2025-222287.4 Wysoka
Improper Authorization org.apache.tomcat:tomcat-catalina Dependency in Jira Service Management Data Center and ServerCVE-2025-467017.3 Wysoka
Idź do oryginalnego materiału