Tech »  Topic »  Atlassian Patches Vulnerabilities in Bamboo, Bitbucket, Confluence, Crowd

Atlassian Patches Vulnerabilities in Bamboo, Bitbucket, Confluence, Crowd


Atlassian’s September 2024 monthly security bulletin details multiple high-severity vulnerabilities in four products.

Atlassian on Wednesday announced patches for multiple high-severity vulnerabilities in Bamboo, Bitbucket, Confluence, and Crowd.

A total of four bugs were addressed in these products, all four allowing attackers to cause denial-of-service (DoS) conditions, Atlassian’s September 2024 security bulletin reveals.

The company updated Bamboo Data Center and Server to address CVE-2024-34750, a security defect in Coyote, a connector component of Apache Tomcat.

“When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain open which should have been closed,” a NIST advisory reads.

The issue can be targeted by unauthenticated attackers to “expose assets in your environment susceptible to exploitation” with no ...


Copyright of this story solely belongs to securityweek . To see the full text click HERE