Security Bulletin - October 17 2023

Still need help?

The Atlassian Community is here for you.

Ask the community

October 2023 Security Bulletin

It is important to note that the issues included in this bulletin are a recent increase in scope of our disclosures, previously we focused on disclosing first-party, critical-severity vulnerabilities via critical advisories. The high-severity vulnerabilities included in this bulletin have a lower impact from the critical advisories we have published previously. While this change results in an increase of visibility and disclosures, it does not mean there are more vulnerabilities. Rather, that we are taking a more proactive approach to vulnerability transparency and are committed to providing our customers with the information they need to make informed decisions about updating our products.

The vulnerabilities reported in this security bulletin include 2 critical and 26 high-severity vulnerabilities which have been fixed in new versions of our products, released in the last month. These vulnerabilities are discovered via our Bug Bounty program and pen-testing processes, as well as third party library scans.

tip/resting Created with Sketch.

Questions about the bulletin? Read more about this new format here.

Released Security Vulnerabilities
SummarySeverityCVSS ScoreAffected VersionsCVE IDMore DetailsPublic Date

Broken Access Control Vulnerability in Confluence Data Center and Server

Critical

10.0

All versions of Confluence Data Center and Server including and after 8.0.0

CVE-2023-22515

View Advisory

Oct 4, 2023

XXE (XML External Entity Injection) in Jira Service Management Data Center and ServerCritical9.8All versions of Jira Service Management Data Center and Server including and after 4.20.0CVE-2019-13990View AdvisoryOct 17, 2023

RCE (Remote Code Execution) in Sourcetree for Mac and Windows

High

7.8

All Windows versions including and after 3.4.0

All Mac versions including and after 4.1.0

CVE-2023-22514

SRCTREE-8076

Oct 17, 2023

com.google.protobuf:protobuf-java Vulnerability in Jira Service Management Data Center and ServerHigh7.5All versions including and after 4.20.0CVE-2022-3509JSDSERVER-14755Oct 17, 2023
com.google.protobuf:protobuf-java Vulnerability in Jira Service Management Data Center and ServerHigh7.5All versions including and after 4.20.0CVE-2022-3171JSDSERVER-14754Oct 17, 2023
com.google.protobuf:protobuf-java Vulnerability in Jira Service Management Data Center and ServerHigh5.5All versions including and after 4.20.0CVE-2021-22569JSDSERVER-14753Oct 17, 2023
FasterXML Vulnerability in Jira Service Management Data Center and ServerHigh7.5All versions including and after 4.20.0CVE-2022-42004JSDSERVER-14752Oct 17, 2023
FasterXML Vulnerability in Jira Service Management Data Center and ServerHigh7.5All versions including and after 4.20.0CVE-2022-42003JSDSERVER-14751Oct 17, 2023
jackson-databind Vulnerability in Jira Service Management Data Center and ServerHigh7.5All versions including and after 4.20.0CVE-2021-46877JSDSERVER-14750Oct 17, 2023
jackson-databind Vulnerability in Jira Service Management Data Center and ServerHigh7.5All versions including and after 4.20.0CVE-2020-36518JSDSERVER-14749Oct 17, 2023
Json-smart Vulnerability in Jira Service Management Data Center and ServerHigh7.5All versions including and after 4.20.0CVE-2021-31684JSDSERVER-14748Oct 17, 2023
Json-smart Vulnerability in Jira Service Management Data Center and ServerHigh7.5All versions including and after 4.20.0CVE-2023-1370JSDSERVER-14746Oct 17, 2023
Apache Kafka Connect API Vulnerability in Bitbucket Data Center and ServerHigh8.8All versions including and after 7.21.0CVE-2023-25194BSERV-18834Oct 17, 2023
FasterXML Vulnerability in Bitbucket Data Center and ServerHigh7.5All versions including and after 7.17.0CVE-2022-42004BSERV-18833Oct 17, 2023
FasterXML Vulnerability in Bitbucket Data Center and ServerHigh7.5All versions including and after 7.17.0CVE-2022-42003BSERV-18832Oct 17, 2023
jackson-databind Vulnerability in Bitbucket Data Center and ServerHigh7.5All versions including and after 7.17.0CVE-2021-46877BSERV-18831Oct 17, 2023
jackson-databind Vulnerability in Bitbucket Data Center and ServerHigh7.5All versions including and after 7.17.0CVE-2020-36518BSERV-18830Oct 17, 2023
com.google.code.gson Vulnerability in Bitbucket Data Center and ServerHigh7.5All versions including and after 7.17.0CVE-2022-25647BSERV-18793Oct 17, 2023
Jettison Vulnerability in Bitbucket Data Center and ServerHigh7.5All versions including and after 7.17.0CVE-2022-45685BSERV-18790Oct 17, 2023
hutool-json Vulnerability in Bitbucket Data Center and ServerHigh7.5All versions including and after 7.17.0CVE-2022-45688BSERV-18789Oct 17, 2023
Woodstox Vulnerability in Bamboo Data Center and ServerHigh7.5All versions including and after 9.1.0CVE-2022-40152BAM-25155Oct 17, 2023
FasterXML Vulnerability in Bamboo Data Center and ServerHigh7.5All versions including and after 9.1.0CVE-2022-42004BAM-25154Oct 17, 2023
FasterXML Vulnerability in Bamboo Data Center and ServerHigh7.5All versions including and after 9.1.0CVE-2022-42003BAM-25153Oct 17, 2023
jackson-databind Vulnerability in Bamboo Data Center and ServerHigh7.5All versions including and after 9.1.0CVE-2021-46877BAM-25152Oct 17, 2023
jackson-databind Vulnerability in Bamboo Data Center and ServerHigh7.5All versions including and after 9.1.0CVE-2020-36518BAM-25151Oct 17, 2023
org.apache.tomcat:tomcat-catalina Vulnerability in Bamboo Data Center and ServerHigh7.5All versions including and after 9.2.2CVE-2023-28709BAM-22601Oct 17, 2023

What you need to do

To fix all the vulnerabilities in this bulletin, Atlassian recommends upgrading your instances to the latest version, if you're unable to do so, upgrade to the minimum fix version in the table below.

ProductFix Recommendation

Confluence Server and Data Center

Upgrade to a minimum fix version of 8.3.3, 8.4.3, 8.5.2 or latest

Jira Service Management Data Center and ServerUpgrade to a minimum fix version of 4.20.27, 5.4.11 or latest
Bitbucket Data Center and ServerUpgrade to a minimum fix version of 7.21.16, 8.9.4, 8.10.4, 8.11.3,8.12.1, 8.13.1 or latest
Bamboo Data Center and ServerUpgrade to a minimum fix version of 9.2.5, 9.3.1, 9.3.3 or latest
Sourcetree for WindowsUpgrade to a minimum fix version of 3.4.15 or latest

Sourcetree for Mac

Upgrade to minimum fix version of 4.2.5 or latest

To search for CVEs or check your products versions for disclosed vulnerabilities, check the Vulnerability Disclosure Portal

Last modified on Oct 20, 2023

Was this helpful?

Yes
No
Provide feedback about this article
Powered by Confluence and Scroll Viewport.