Security Bulletin - September 19 2023

Security Advisories & Bulletins

On this page

Still need help?

The Atlassian Community is here for you.

Ask the community

September 2023 Security Bulletin

It is important to note that the issues included in this bulletin are a recent increase in scope of our disclosures, previously we focused on disclosing first-party, critical-severity vulnerabilities via critical advisories. The high-severity vulnerabilities included in this bulletin have a lower impact from the critical advisories we have published previously. While this change results in an increase of visibility and disclosures, it does not mean there are more vulnerabilities. Rather, that we are taking a more proactive approach to vulnerability transparency and are committed to providing our customers with the information they need to make informed decisions about updating our products.

The vulnerabilities reported in this security bulletin include 4 high-severity vulnerabilities which have been fixed in new versions of our products, released in the last month. These vulnerabilities are discovered via our Bug Bounty program and pen-testing processes, as well as third party library scans.

tip/resting Created with Sketch.

Questions about the bulletin? Read more about this new format here.

Released Security Vulnerabilities
SummarySeverityCVSS ScoreAffected VersionsCVE IDMore DetailsPublic Date
Patch Management in Jira Service Management Data Center and ServerHigh7.5>= 4.20.0
>= 5.4.8
>= 5.9.1
>= 5.10.0
&
< 4.20.25
< 5.4.9
< 5.9.2
< 5.10.1
< 5.11.0
CVE-2022-25647JSDSERVER-14007Sep 19, 2023
DoS (Denial of Service) in Confluence Data Center and ServerHigh7.5>= 5.6
&
< 7.19.13
< 7.19.14
< 8.5.1
< 8.6.0
CVE-2023-22512CONFSERVER-91258Sep 19, 2023
RCE (Remote Code Execution) in Bitbucket Data Center and ServerHigh8.5>= 8.0.0
>= 8.1.0
>= 8.2.0
>= 8.3.0
>= 8.4.0
>= 8.5.0
>= 8.6.0
>= 8.7.0
>= 8.8.0
>= 8.9.0
>= 8.10.0
>= 8.11.0
>= 8.12.0
>= 8.13.0
&
< 8.9.5
< 8.10.5
< 8.11.4
< 8.12.2
< 8.13.1
< 8.14.0
CVE-2023-22513BSERV-14419Sep 19, 2023
Third-Party Dependency in Bamboo Data Center and ServerHigh7.5>= 8.1.12
>= 8.2.9
>= 9.0.4
>= 9.1.3
>= 9.2.3
>= 9.3.0
&
< 9.2.4
< 9.3.1
CVE-2023-28709BAM-22479Sep 19, 2023

What you need to do

To fix all the vulnerabilities in this bulletin, Atlassian recommends upgrading your instances to the latest version, if you're unable to do so, upgrade to the minimum fix version in the table below.

ProductFix Recommendation
Jira Service Management Server and Data CenterUpgrade to a minimum fix version of 4.20.25, 5.4.9, 5.9.2, 5.10.1, 5.11.0 or latest
Confluence Server and Data CenterUpgrade to a minimum fix version of 7.19.13, 7.19.14, 8.5.1, 8.6.0 or latest
Bitbucket Server and Data CenterUpgrade to a minimum fix version of 8.9.5, 8.10.5, 8.11.4, 8.12.2, 8.13.1, 8.14.0 or latest
Bamboo Server and Data CenterUpgrade to a minimum fix version of 9.2.4, 9.3.1 or latest

To search for CVEs or check your products versions for disclosed vulnerabilities, check the Vulnerability Disclosure Portal

Last modified on Sep 29, 2023

Was this helpful?

Yes
No
Provide feedback about this article
Powered by Confluence and Scroll Viewport.