Security patches: Atlassian secures Confluence & Co. against possible attacks
Among others, Atlassian Bamboo and Jira Data Center and Server are susceptible to various attacks.
(Image: Alfa Photo/Shutterstock.com)
Atlassian has released important security updates for Bamboo, Bitbucket, Confluence, Crowd, Jira, and Jira Service Management Data Center and Server. Following successful attacks, attackers can primarily trigger DoS conditions and thus crashes.
Probably not critical in this context
A warning message indicates, among other things, that the developers have closed two “critical” vulnerabilities (CVE-2025-12383, CVE-2025-66516). These affect Eclipse Jersey and Apache Tika, which Bamboo and Confluence Data Center and Server use. The developers explain that the vulnerabilities do not directly impact the Atlassian applications, and therefore a lower threat level applies. If attacks are successful, for example, actually untrusted servers can be classified as trusted.
The remaining security vulnerabilities are classified with the threat level “high.” Here, attackers can initiate DoS attacks (e.g., CVE-2025-52999). However, malicious code can also get onto systems (e.g., CVE-2025-55752). Furthermore, attackers can intercept connections as man-in-the-middle (CVE-2025-49146).
Videos by heise
Atlassian's warning message provides no indication that attackers are already exploiting the vulnerabilities. However, such things can change quickly, and admins should install the available security updates promptly. According to the developers, all previous versions are vulnerable.
- Bamboo Data Center and Server:
12.0.2 Data Center Only
10.2.13 to 10.2.14 (LTS) recommended Data Center Only
9.6.21 to 9.6.22 (LTS) Data Center Only
- Bitbucket Data Center and Server:
10.1.1 to 10.1.4 Data Center Only
9.4.15 to 9.4.16 (LTS) recommended Data Center Only
8.19.26 to 8.19.27 (LTS) Data Center Only
- Confluence Data Center and Server:
10.2.2 (LTS) recommended Data Center Only
9.2.13 (LTS) Data Center Only
- Crowd Data Center and Server:
7.1.3 recommended Data Center Only
6.3.4 Data Center Only
- Jira Data Center and Server:
11.3.0 to 11.3.1 (LTS) recommended Data Center Only
11.2.1 Data Center Only
10.3.16 (LTS) Data Center Only
9.12.26 to 9.12.31 (LTS)
- Jira Service Management Data Center and Server:
11.3.1 (LTS) recommended Data Center Only
11.2.1 Data Center Only
10.3.16 (LTS) Data Center Only
5.12.29 to 5.12.31 (LTS)
(des)