Are Atlassian products affected by the Java deserialization vulnerability?

Laszlo Major
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
November 12, 2015

http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/

This has hit the news a few days ago. I haven't found any official Atlassian statements yet. Are Atlassian products affected by this?

1 answer

0 votes
Marcin Gardias
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
November 12, 2015

This vulnerability has been patched recently in Bamboo. Please upgrade if your version is affected.

The official security advisory:

https://confluence.atlassian.com/bamboo/bamboo-security-advisory-2015-10-21-785452575.html

 

Peter Anderson
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
December 8, 2015

Are Jira or Confluence vulnerable to this also?

Suggest an answer

Log in or Sign up to answer