Security

Atlassian security advisory reveals four fresh critical flaws – in mail with dead links

Bitbucket, Confluence and Jira all in danger, again. Sigh


Atlassian has emailed its customers to warn of four critical vulnerabilities, but the message had flaws of its own – the links it contained weren't live for all readers at the time of despatch.

The email, seen by The Register, warns of flaws rated 9.0 or higher on the Common Vulnerability Scoring System (CVSS) scale and offers a link to an advisory.

But that link was to a page that did not describe the relevant flaws, instead detailing CVE-2023-22518, the 9.1-rated stinker revealed in late October and later upgraded to a perfect 10/10. Nor did links to the four CVEs the email mentions reach the correct page for around an hour – all produced a Page Not Found error and a suggestion that the page may have been renamed with another URL that does carry the correct information.

Atlassian told us "There was a small error where emails went out to some customers with broken links. As soon as we realized we put a workaround in place so customers were redirected to the appropriate pages. We apologize to our customers for any frustration caused with our mistake."

The URLs all include URLdefense.com – a service offered by Proofpoint. Maybe it was Proofpoint's problem.

While the links were dead, Atlassian did manage to publish info about the four fresh problems here.

The four flaws all allow remote code execution and impact the products listed below:

The fix for all the flaws is the same: upgrade the product to a fixed version.

Atlassian's emailed advisory urges "you must take immediate action to protect your instance." The Register imagines that was a hard instruction to follow, given the dud links the email contained for some customers.

Atlassian's stated company values include "Don't #@!% the customer" and "Open company, no bullshit." ®

Send us news
7 Comments

Dump C++ and in Rust you should trust, Five Eyes agencies urge

Memory safety vulnerabilities need to be crushed with better code

Polish train maker denies claims its software bricked rolling stock maintained by competitor

Says it was probably hacked, which isn't good news either

Weak session keys let snoops take a byte out of your Bluetooth traffic

BLUFFS spying flaw present in iPhones, ThinkPad, plenty of chipsets

Proposed US surveillance regime would enlist more businesses

Expanded service provider definition could force cafes and hotels to spy for the feds

Boffins fool AI chatbot into revealing harmful content – with 98 percent success rate

This one weird trick works every time, most of the time

Boffins devise 'universal backdoor' for image models to cause AI hallucinations

Data poisoning appears open to all

Five Eyes nations warn Moscow's mates at the Star Blizzard gang have new phishing targets

The Russians are coming! Err, they've already infiltrated UK, US inboxes

BlackBerry squashes plan to spin out its IoT biz

Board and incoming CEO decide reorganizing is better than splitting

Microsoft issues deadline for end of Windows 10 support – it's pay to play for security

Limited options will be available into 2028, for an undisclosed price

Open source forkers stick an OpenBao in the oven

HashiCorp software faces challenge after licensing change

Cisco intros AI to find firewall flaws, warns this sort of thing can't be free

Predicts cyber crims will find binary brainboxes harder to battle

2.5M patients infected with data loss in Norton Healthcare ransomware outbreak

AlphV lays claims to the intrusion