Help Net Security reports that attackers have already started trying to exploit a critical arbitrary file access flaw in Atlassian’s self-managed Data Center products, including Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible and Fisheye. Atlassian urged customers to upgrade to a fixed version as soon as possible. Those who cannot update quickly should remove vulnerable instances from the internet or block external access, and check access logs for signs of compromise.
Source: helpnetsecurity.com
Share
…


