Security Bulletin 02/2025 investigating

Incident Report for Communardo Service Center

Resolved

Dear customers,

after a thorough analysis, we recommend installing a minor update to the affected systems: Crowd, Bitbucket, Confluence (only if application runs on case insensitive filesystem) and consider the updates for Bamboo & Jira to be optional.
We assessed the risk for Confluence as "medium" if the application is running on a case insensitive filesystem and low if running on a case sensitive filesystem. For Bamboo we assessed the risk as "low", for Jira as "low", for Crowd as "medium" and for Bitbucket as "medium".

You can find all the information regarding the fixed versions for your system in the post: https://confluence.atlassian.com/security/security-bulletin-february-18-2025-1510670627.html

As mentioned, if we are hosting your systems or proactively update your applications, we will directly communicate any information via the opened tickets (which have been created in the meantime) in our service center.

In case you have additional questions, please open a request in our Communardo Service Center:
https://communardo.atlassian.net/servicedesk/customer/portal/6

Best regards,
Your Communardo Team
Posted Feb 19, 2025 - 11:29 CET

Investigating

Dear customers,

we are currently evaluating Atlassian's latest Security Bulletin:
https://confluence.atlassian.com/security/security-bulletin-february-18-2025-1510670627.html

Affected Applications:
Bamboo, Bitbucket, Confluence, Crowd, Jira

We will update this post as soon as we have finalized the analysis.

If we are hosting your systems or if we proactively update your applications, we will open a Ticket soon.

In case you have additional questions, please open a request in our Communardo Service Center:
https://communardo.atlassian.net/servicedesk/customer/portal/6

Best Regards,
Your Communardo Team
Posted Feb 18, 2025 - 19:24 CET
This incident affected: Atlassian-Security (Security Status Bamboo, Security Status Bitbucket, Security Status Confluence, Security Status Crowd, Security Status Crucible/Fisheye, Security Status Jira).