I've recently migrated from Snyk Scan pipe to Bitbucket Dependency Scanner, but I'm running into an issue. I'm using script: - pipe: atlassian/bitbucket-dependency-scanner:0.5.0 variables: ...
Hi, Is there a way to access code insight report generated after bitbucket dependency scan? I want to upload this insights report to artifact so that i can access in the next steps in the pi...
Specific error message: Status: Downloaded newer image for bitbucketpipelines/bitbucket-dependency-scanner:0.1.4 time="2024-11-19T16:21:25Z" level=error msg="error waiting for ...
...nalyzer (2 seconds) [INFO] Finished False Positive Analyzer (0 seconds) [INFO] Finished NVD CVE Analyzer (0 seconds) [INFO] Finished Sonatype OSS Index Analyzer (0 seconds) [INFO] Finished V...
while im using the pipe bitbucket dependency scanner its getting failed.
...ffline file instead of Api key? Can i download an deprecated version and use the import/assset/cve folder or maby can i spoof the api key from NVD and point to a json file?
I'd like to know if Atlassian was impacted by any of these: CVE-2023-46805 (Authentication Bypass) in the web component of Ivanti ICS CVE-2024-21887 (Command Injection) for Ivanti Connect S...
Hi all I need to set up an nvd assets database. I'm using the cve import module, is there any possibility to use this solution ofline? I saw that in a previus version there was a ofline-m...
Take immediate action to protect your instance We have discovered that Confluence Data Center and Server customers on out-of-date versions including 8.4.5 are vulnerable to a remote code execution ...
...nstructions. CVE-2023-22524 - RCE Vulnerability in Atlassian Companion app for MacOS Confluence Data Center and Server (former and present customers) CVE-2023-22523 - RCE Vulnerability in A...
...mmediate action to protect their instances. Please carefully review all of the Critical Security Advisories impacting your Atlassian product(s) to verify affected versions and instructions. CVE-2023-2...
Atlassian has disclosed a CVE that impacts Bamboo Data Center and Bamboo Server today. This particular CVE affects all previous versions of Bamboo. Please see the full advisory in https://c...
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24998 https://nvd.nist.gov/vuln/detail/CVE-2023-24998 Still waiting for an "Official" response from Atlassian. We've found the l...
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23529
Our security scanning software is complaining about Apache Commons Text within our Confluence installation. When will Atlassian be posting guidance/remediation on this issue?
Does the reported vulnerability CVE-2022-36804 affect the confluence tool?
This advisory is a critical severity security vulnerability that was introduced in version 7.0.0 of Bitbucket Server and Data Center. All versions released after 6.10.17 including 7.0.0 and newer are...
Hi, as i can see in https://confluence.atlassian.com/security/multiple-products-security-advisory-cve-2022-26136-cve-2022-26137-1141493031.html our used jira & confluence versions are l...
What action should cloud customers (Confluence) need to take to keep corporate information secure? Is there any corrective action that customers need to take?
Hi , We are using a vunelrable jira server edition. 8.19.X for CVE-2022-26135 - Full-Read Server Side Request Forgery in Mobile Plugin for Jira Data Center and Server. But t...
Atlassian has published security advisory CVE-2022-0540 today, 29 June 2022. This advisory is in regards to and affects the Jira Server Mobile Plugin which is bundled with Jira and Jira S...
Good Afternoon, I have remediated CVE-2022-26134 with the temporary workaround in our stage environment for now and wanted to verify before doing the same to prod. Is there a script or a c...
Hello, We are using version 8.20.1 as jira server. However, we received a vulnerability notice today. CVE-2020-14179 we've done the readings for the issue here. I couldn't find such an open number o...
See: https://lists.apache.org/thread/6ckmjfb1k61dyzkto9vm2k5jvt4o7w7c Would be great to have an Atlassian response/FAQ page similar to this one.
Regarding the recently announced critical security advisory for CVE-2022-0540 regarding Authentication bypass in JIRA Server, is this still a critical vulnerability if the JIRA instance is confined t...
Copied to clipboard