Are Atlassian products affected by the Java deserialization vulnerability?

Laszlo Major November 12, 2015

http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/

This has hit the news a few days ago. I haven't found any official Atlassian statements yet. Are Atlassian products affected by this?

1 answer

0 votes
Marcin Gardias
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
November 12, 2015

This vulnerability has been patched recently in Bamboo. Please upgrade if your version is affected.

The official security advisory:

https://confluence.atlassian.com/bamboo/bamboo-security-advisory-2015-10-21-785452575.html

 

Peter Anderson December 8, 2015

Are Jira or Confluence vulnerable to this also?

Suggest an answer

Log in or Sign up to answer