セキュリティ情報 - 2024 年 1 月 16 日

January 2024 Security Bulletin

The vulnerabilities reported in this security bulletin include 28 high-severity vulnerabilities which have been fixed in new versions of our products, as detailed below. These vulnerabilities are discovered via our Bug Bounty program and pen-testing processes, as well as third-party library scans. 

NOTE: The vulnerabilities included in monthly Security Bulletins present a lower impact than those published via Critical Security Advisories. Customers can expect to receive those high-priority patches outside of our monthly schedule as necessary. 

To search for CVEs or check your product versions for disclosed vulnerabilities, check the Vulnerability Disclosure Portal.

リリースされたセキュリティ脆弱性
要約深刻度CVSS スコア影響を受けるバージョンCVE ID詳細情報公開日
Request Smuggling org.apache.tomcat:tomcat-coyote Dependency in Jira Software Data Center and Server7.5All versions including and after 9.4.0CVE-2022-42252JSWSERVER-254682024 年 1 月 16 日
XXE (XML External Entity Injection) jackson-databind Dependency in Jira Software Data Center and Server7.5All versions including and after 8.20.0CVE-2020-25649JSWSERVER-254612024 年 1 月 16 日
SSRF org.apache.xmlgraphics:batik-bridge Dependency in Jira Service Management Data Center and Server7.1All versions including and after 4.20.0CVE-2022-44729JSDSERVER-149582024 年 1 月 16 日
Info Disclosure org.apache.santuario:xmlsec Dependency in Crowd Data Center and Server7.5All versions including and after 3.4.6CVE-2021-40690CWD-61902024 年 1 月 16 日
Request Smuggling org.apache.tomcat:tomcat-catalina Dependency in Crowd Data Center and Server7.5All versions including and after 3.4.6CVE-2023-46589CWD-61912024 年 1 月 16 日
DoS (Denial of Service) com.squareup.okio:okio-jvm Dependency in Confluence Data Center and Server7.5All versions including and after 7.13.0CVE-2023-3635CONFSERVER-936232024 年 1 月 16 日
RCE (Remote Code Execution) in Confluence Data Center and Server7.2All versions including and after 7.13.0CVE-2023-22526CONFSERVER-935162024 年 1 月 16 日
RCE (Remote Code Execution) in Confluence Data Center and Server8.3All versions including and after 2.1CONFSERVER-940642024 年 1 月 16 日
RCE (Remote Code Execution) in Confluence Data Center and Server8.0All versions including and after 1.0.0CONFSERVER-940652024 年 1 月 16 日
RCE (Remote Code Execution) in Confluence Data Center and Server8.6All versions including and after 1.0.0CONFSERVER-940662024 年 1 月 16 日
DoS (Denial of Service) org.xerial.snappy:snappy-java Dependency in Bitbucket Data Center and Server7.5All versions including and after 7.21.0CVE-2023-43642BSERV-191002024 年 1 月 16 日
DoS (Denial of Service) ch.qos.logback:logback-core Dependency in Bitbucket Data Center and Server7.5All versions including and after 7.21.0CVE-2023-6481BSERV-190992024 年 1 月 16 日
DoS (Denial of Service) ch.qos.logback:logback-core Dependency in Bitbucket Data Center and Server7.5All versions including and after 7.21.0CVE-2023-6378BSERV-190982024 年 1 月 16 日
Request Smuggling org.apache.tomcat.embed:tomcat-embed-core Dependency in Bitbucket Data Center and Server7.5All versions including and after 7.21.0CVE-2023-46589BSERV-190972024 年 1 月 16 日
DoS (Denial of Service) org.xerial.snappy:snappy-java Dependency in Bitbucket Data Center and Server7.5All versions including and after 7.21.0CVE-2023-34455BSERV-190962024 年 1 月 16 日
DoS (Denial of Service) org.xerial.snappy:snappy-java Dependency in Bitbucket Data Center and Server7.5All versions including and after 7.21.0CVE-2023-34454BSERV-190952024 年 1 月 16 日
DoS (Denial of Service) org.xerial.snappy:snappy-java Dependency in Bitbucket Data Center and Server7.5All versions including and after 7.21.0CVE-2023-34453BSERV-190942024 年 1 月 16 日
DoS (Denial of Service) org.eclipse.jetty:jetty-http Dependency in Bitbucket Data Center and Server7.5All versions including and after 8.9.0CVE-2023-36478BSERV-190442024 年 1 月 16 日
DoS (Denial of Service) org.json:json Dependency in Bitbucket Data Center and Server7.5All versions including and after 7.17.0CVE-2023-5072BSERV-190372024 年 1 月 16 日
DoS (Denial of Service) org.eclipse.jetty:jetty-http Dependency in Bamboo Data Center and Server7.5All versions including and after 9.2.1CVE-2023-36478BAM-256232024 年 1 月 16 日
DoS (Denial of Service) org.apache.avro:avro Dependency in Bamboo Data Center and Server7.5All versions including and after 9.2.1CVE-2023-39410BAM-256222024 年 1 月 16 日
RCE (Remote Code Execution) org.jvnet.hudson:xstream Dependency in Bamboo Data Center and Server8.8All versions including and after 9.2.1CVE-2020-26217BAM-256142024 年 1 月 16 日
DoS (Denial of Service) org.jvnet.hudson:xstream Dependency in Bamboo Data Center and Server7.5All versions including and after 9.2.1CVE-2017-7957BAM-256132024 年 1 月 16 日
Info Disclosure org.codehaus.plexus:plexus-utils Dependency in Bamboo Data Center and Server7.5All versions including and after 9.2.1CVE-2022-4244BAM-256122024 年 1 月 16 日
RCE (Remote Code Execution) com.h2database:h2 Dependency in Bamboo Data Center and Server8.8All versions including and after 9.1.0CVE-2018-10054BAM-256092024 年 1 月 16 日
DoS (Denial of Service) org.json:json Dependency in Bamboo Data Center and Server7.5All versions including and after 9.2.3CVE-2023-5072BAM-256072024 年 1 月 16 日
Request Smuggling org.apache.tomcat:tomcat-catalina Dependency in Bamboo Data Center and Server7.5All versions including and after 9.2.1CVE-2023-46589BAM-256062024 年 1 月 16 日
DoS (Denial of Service) com.fasterxml.woodstox:woodstox-core Dependency in Bamboo Data Center and Server7.5All versions including and after 9.2.1CVE-2022-40152BAM-256402024 年 1 月 16 日

必要なアクション

To fix all the vulnerabilities in this bulletin, Atlassian recommends patching your instances to the latest version. If you're unable to do so, patch to the minimum fix version in the table below.

製品推奨される修正
Bitbucket Data CenterPatch to a minimum fix version of 7.21.21, 8.9.9, 8.13.5, 8.14.4, 8.15.3, 8.16.2, 8.17.0 or latest
Bitbucket ServerPatch to a minimum fix version of 7.21.21, 8.9.9, 8.13.5, 8.14.4
Bamboo Data Center and ServerPatch to a minimum fix version of 9.2.9, 9.3.6, 9.4.2 or latest
Jira Data Center および ServerPatch to a minimum fix version of 9.4.13, 9.7.0 or latest
Jira Service Management Data Center および ServerPatch to a minimum fix version of 4.20.30, 5.4.15, 5.12.2 or latest
Crowd Data Center and ServerPatch to a minimum fix version of 5.2.2 or latest
Confluence Data CenterPatch to a minimum fix version of 7.19.18, 8.5.5, 8.7.2 or latest
Confluence ServerPatch to a minimum fix version of 7.19.18, 8.5.5

To search for CVEs or check your products versions for disclosed vulnerabilities, check the Vulnerability Disclosure Portal.

最終更新日: 2024 年 1 月 26 日

この内容はお役に立ちましたか?

はい
いいえ
この記事についてのフィードバックを送信する
Powered by Confluence and Scroll Viewport.