Hi,
I came across one of the Scurity Issues/Vulnerability
https://cloudsek.com/security-flaw-in-atlassian-products-jira-confluencetrello-bitbucket-affecting-multiple-companies/
This has been tested.
Just wanted to highlight here.
Thank you, @Ajay Mishra, for the heads up!
Have you contacted Atlassian directly? Is there any other publicly available information about the vulnerability?
I didn't find anything neither under https://www.atlassian.com/trust/security/advisories, nor under https://www.cvedetails.com/vulnerability-list/vendor_id-3578/Atlassian.html, nor https://jira.atlassian.com/issues/?jql=issuetype%20%3D%20%22Public%20Security%20Vulnerability%22%20ORDER%20BY%20updated%20DESC.
Regards,K.
@Kalin U
hi
This vulnerability was highlighted by Cloudesk
Thank you for bringing this up on the Trust & Security Community. Atlassian's security team is aware of this incident and we have followed security protocol to invalidate affected session tokens. Atlassian is conducting a comprehensive investigation, though our security team has not found evidence of a compromise within our systems or products. No customer action is required at this time. We will share another update once our investigation concludes.
Hi Dawn,
Is this available somewhere as an official message/advice?
Thanks,
Andrew
It looks like you're new here. Sign in or register to get started.