← Back to the feed

Atlassian urges urgent upgrades after critical flaw exposes files in eight products

The Register ·

Atlassian has warned users of a critical security vulnerability in eight datacenter products that allows unauthenticated attackers to access specific files. The flaw, rated 9.3 in severity and affecting Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible and Fisheye, is particularly concerning because some configurations may harbour sensitive files.

The vulnerability requires attackers to know the exact filename and path to exploit it, and does not permit viewing directory contents, which limits its scope. Atlassian has released patched versions and urges users to upgrade immediately; those unable to patch quickly should take affected instances offline from the public internet. Cloud users face no risk, as the company maintains its own SaaS infrastructure separately.

  • Atlassian warns of critical file access flaw in eight datacenter products.
  • Attackers need exact filename/path; patched versions now available.
  • Cloud users unaffected; offline or upgrade immediately.

New here? Start with this

Atlassian is a major software company whose products are used by thousands of organisations around the world. Their most well-known tools include Jira for project management, Confluence for sharing documents, and Bitbucket for storing code.

A critical security flaw has been discovered in eight of Atlassian's products that allows attackers to access files on affected servers without logging in first. The flaw is limited in scope because attackers must know the exact filename and path of what they want to access; they cannot browse the server to discover files on their own.

This is concerning because organisations may store sensitive information like passwords or confidential business data on these servers. The vulnerability affects only organisations that run Atlassian products on their own equipment; companies using Atlassian's cloud service are unaffected.

Software

Read the full article at the source →

Originally published by The Register as “Atlassian warns of critical file access flaw in its datacenter products”.