CERT-In Vulnerability Note
CIVN-2024-0258
Multiple Vulnerabilities in Atlassian Products
Original Issue Date:August 21, 2024
Severity Rating: HIGH
Software Affected
- Bamboo Data Center and Server
- Confluence Data Center and Server
- Crowd Data Center and Server
- Jira Data Center and Server
- Jira Service Management Data Center and Server
Overview
Multiple vulnerabilities have been reported in Atlassian Products which could allow an attacker to execute arbitrary code, perform reflected XSS (cross-site scripting) attacks, CSRF (cross-site request forgery) attack, SSRF (server-side request forgery) attack, obtain sensitive information and cause denial of service condition on the targeted system.
Description
Multiple vulnerabilities have been reported in various Atlassian Products:
Solution
Apply appropriate updates as mentioned in Atlassian security bulletin:
https://confluence.atlassian.com/security/security-bulletin-august-20-2024-1431535667.html
Vendor Information
Atlassian
https://confluence.atlassian.com/security/security-bulletin-august-20-2024-1431535667.html
References
Atlassian
https://confluence.atlassian.com/security/security-bulletin-august-20-2024-1431535667.html
CVE Name
CVE-2024-21689
CVE-2024-21690
CVE-2024-22243
CVE-2024-22259
CVE-2024-22262
CVE-2024-29857
CVE-2024-34750
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|