Atlassian Releases Security Updates for Bitbucket Data Center and Confluence Data Center
Updates address critical RCE vulnerabilities
Summary
Updates address critical RCE vulnerabilities
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Atlassian has released an advisory that addresses vulnerabilities that originate with third-party software Hazelcast. Hazelcast is used when the Atlassian products are configured to run as a cluster.
The vulnerability known as CVE-2016-10750 affects Confluence Data Center and is open to Java deserialisation attacks. Similarly, CVE-2022-26133 can result in an affected system being vulnerable to Java deserialisation attacks, but it is specific to Bitbucket and has a CVSS score of 10.
A remote, unauthenticated attacker could exploit these vulnerabilities by sending a specially crafted request, resulting in remote code execution (RCE) and allow the attacker to take control of the system.
Remediation advice
Affected organisations are encouraged to review the Atlassian Multiple Products Security Advisory Hazelcast Vulnerable To Remote Code Execution and apply the necessary updates or workarounds.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 22 April 2022 4:57 pm