Atlassian fixes DoS vulnerabilities in its Products

Atlassian fixes DoS vulnerabilities in its Products


Atlassian releases patches for high-severity vulnerabilities in Bamboo, Bitbucket, Confluence, and Crowd.

There are four vulnerabilities addressed in these products, all four allowing attackers to cause denial-of-service (DoS) conditions.

The vulnerability in Bamboo Data Center and Server tracked as CVE-2024-34750 with a CVSS score of 7.5, stems in Coyote, a connector component of Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams, which in turn led to the use of an incorrect infinite timeout, which allowed connections to remain open, which should have been closed.

Advertisements

The vulnerability in Bitbucket Data Center and Server received patches for both the Tomcat Coyote flaw and for CVE-2024-32007 with a CVSS score of 7.5, an improper input validation bug in Apache CXF JOSE code, which could allow an attacker to cause a DoS condition by specifying a large value for the p2c parameter in a token.

Two other vulnerabilities were addressed with the latest Crowd Data Center and Server updates, tracked as CVE-2024-29857 with a CVSS score of 7.5 and another in Confluence Datacenter tracked as CVE-2024-22871 with same CVSS score of 7.5.

All the vulnerabilities were reported via its bug bounty program and  Atlassian makes no mention of any of these issues being exploited in the wild but urges users to update their installations to the latest version of each application or to a fixed version as soon as possible.

For more details on affected versions and fixed details, refer to the link

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.