21 kwietnia 2026 r. firma Atlassian opublikowała ostrzeżenie dotyczące bezpieczeństwa w celu usunięcia luk w zabezpieczeniach, w tym kilku krytycznych, w następujących produktach:

  • Bamboo Data Center i Server – wiele wersji
  • Bitbucket Data Center i Server – wiele wersji
  • Confluence Data Center i Server – wiele wersji
  • Jira Data Center i Server – wiele wersji
  • Jira Service Management Data Center i Server – wiele wersji

Luki w zabezpieczeniach zgłoszone w niniejszym Biuletynie Bezpieczeństwa obejmują 31 luk o wysokim stopniu zagrożenia i 7 luk o krytycznym stopniu zagrożenia pochodzących od firm trzecich, które zostały naprawione w nowych wersjach naszych produktów wydanych w zeszłym miesiącu.

ProduktPodatna wersjaPatchLink/OpisNumer CVEKrytyczność
Bamboo Data Center and Server12.1.0 do 12.1.3 (LTS) 12.0.0 do 12.0.2 11.0.0 do 11.0.8 10.2.0 do 10.2.16 (LTS) 10.1.0 do 10.1.1 10.0.0 do 10.0.3 9.6.2 do 9.6.24 (LTS)12.1.6 (LTS) zalecane tylko Data Center 10.2.18 (LTS) Tylko Data CenterDoS (Denial of Service) io.netty:netty-codec-http2 Dependency in Bamboo Data CenterCVE-2026-338718.7 Wysoka
OS Command Injection in Bamboo Data Center – CVE-2026-21571CVE-2026-215719.4 Krytyczna
HTTP Request Smuggling org.apache.tomcat:tomcat-catalina Dependency in Bamboo Data CenterCVE-2026-248807.5 Wysoka
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Bamboo Data CenterCVE-2026-338707.5 Wysoka
MITM (Man-in-the-Middle) org.apache.tomcat:tomcat-coyote Dependency in Bamboo Data CenterCVE-2026-247347.5 Wysoka
DoS (Denial of Service) axios Dependency in Bamboo Data CenterCVE-2026-256397.5 Wysoka
XSS (Cross Site Scripting) dompurify Dependency in Bamboo Data CenterCVE-2024-458017.3 Wysoka
Bitbucket Data Center and Server10.1.1 do 10.1.5 10.0.1 do 10.0.2 9.4.12 do 9.4.17 (LTS)10.2.0 do 10.2.2 (LTS) zalecane tylko Data Center 9.4.18 do 9.4.19 (LTS) Tylko Data CenterDoS (Denial of Service) ua-parser-js Dependency in Bitbucket Data CenterCVE-2022-259277.5 Wysoka
Confluence Data Center and Server10.2.0 do 10.2.7 (LTS) 10.1.0 do 10.1.2 10.0.2 do 10.0.3 9.5.1 do 9.5.4 9.4.0 do 9.4.1 9.3.1 do 9.3.2 9.2.0 do 9.2.17 (LTS) 9.1.0 do 9.1.1 9.0.1 do 9.0.3 8.9.1 do 8.9.810.2.10 (LTS) zalecane tylko Data Center 9.2.19 (LTS) Tylko Data CenterRCE (Remote Code Execution) org.yaml:snakeyaml Dependency in Confluence Data CenterCVE-2022-14719.8 Krytyczna
Path Traversal (Arbitrary Write) node-tar Dependency in Confluence Data CenterCVE-2026-239508.8 Wysoka
DoS (Denial of Service) io.netty:netty-codec-http2 Dependency in Confluence Data CenterCVE-2026-338718.7 Wysoka
Injection immutable Dependency in Confluence Data CenterCVE-2026-290638.7 Wysoka
File Inclusion node-tar Dependency in Confluence Data CenterCVE-2026-237458.2 Wysoka
File Inclusion node-tar Dependency in Confluence Data CenterCVE-2026-248428.2 Wysoka
File Inclusion node-tar Dependency in Confluence Data CenterCVE-2026-318028.2 Wysoka
DOM-based XSS @remix-run/router Dependency in Confluence Data CenterCVE-2026-220298 Wysoka
DoS (Denial of Service) valibot Dependency in Confluence Data CenterCVE-2025-660207.5 Wysoka
DoS (Denial of Service) org.bitbucket.b_c:jose4j Dependency in Confluence Data CenterCVE-2024-293717.5 Wysoka
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Confluence Data CenterCVE-2026-338707.5 Wysoka
DoS (Denial of Service) axios Dependency in Confluence Data CenterCVE-2026-256397.5 Wysoka
DoS (Denial of Service) css Dependency in Confluence Data CenterCVE-2023-486317.5 Wysoka
Injection dompurify Dependency in Confluence Data CenterCVE-2024-458017.3 Wysoka
File Inclusion node-tar Dependency in Confluence Data CenterCVE-2026-269607.1 Wysoka
Jira Data Center and Server11.3.0 do 11.3.3 (LTS) 10.7.1 do 10.7.4 10.6.0 do 10.6.1 10.5.0 do 10.5.1 10.4.0 do 10.4.1 10.3.0 do 10.3.18 (LTS) 10.2.0 do 10.2.1 10.1.1 do 10.1.2 10.0.0 do 10.0.1 9.17.0 do 9.17.5 9.16.0 do 9.16.1 9.15.2 9.12.8 do 9.12.33 (LTS)11.3.4 (LTS) zalecane tylko Data Center 10.3.19 (LTS) Tylko Data CentermXSS (mutation Cross-Site Scripting) dompurify Dependency in Jira Software Data Center and ServerCVE-2024-4787510 Krytyczna
RCE (Remote Code Execution) org.yaml:snakeyaml Dependency in Jira Software Data CenterCVE-2022-14719.8 Krytyczna
DoS (Denial of Service) brace-expansion Dependency in Jira Software Data CenterCVE-2026-255479.2 Krytyczna
Improper Authorization commons-beanutils:commons-beanutils Dependency in Jira Software Data CenterCVE-2025-487348.8 Wysoka
MITM (Man-in-the-Middle) com.squareup.okhttp3:okhttp Dependency in Jira Software Data Center and ServerCVE-2021-03417.5 Wysoka
DoS (Denial of Service) net.minidev:json-smart Dependency in Jira Software Data CenterCVE-2023-13707.5 Wysoka
DoS (Denial of Service) com.squareup.okio:okio Dependency in Jira Software Data CenterCVE-2023-36357.5 Wysoka
Jira Service Management Data Center and Server11.3.0 do 11.3.3 (LTS) 11.2.0 do 11.2.1 11.1.0 do 11.1.1 11.0.1 10.7.1 do 10.7.4 10.6.0 do 10.6.1 10.5.0 do 10.5.1 10.4.0 do 10.4.1 10.3.0 do 10.3.18 (LTS) 10.2.0 do 10.2.1 10.1.1 do 10.1.2 10.0.0 do 10.0.1 5.17.0 do 5.17.5 5.16.0 do 5.16.1 5.15.211.3.4 (LTS) zalecane tylko Data Center 10.3.19 (LTS) Tylko Data CentermXSS (mutation Cross-Site Scripting) dompurify Dependency in Jira Service Management Data Center and ServerCVE-2024-4787510 Krytyczna
RCE (Remote Code Execution) org.yaml:snakeyaml Dependency in Jira Service Management Data CenterCVE-2022-14719.8 Krytyczna
MITM (Man-in-the-Middle) xmlhttprequest Dependency in Jira Service Management Data CenterCVE-2021-315979.4 Wysoka
Improper Authorization commons-beanutils:commons-beanutils Dependency in Jira Service Management Data CenterCVE-2025-487348.8 Wysoka
DoS (Denial of Service) com.squareup.okio:okio Dependency in Jira Service Management Data CenterCVE-2023-36357.5 Wysoka
MITM (Man-in-the-Middle) com.squareup.okhttp3:okhttp Dependency in Jira Service Management Data Center and ServerCVE-2021-03417.5 Wysoka
DoS (Denial of Service) brace-expansion Dependency in Jira Service Management Data CenterCVE-2026-255477.5 Wysoka
DoS (Denial of Service) net.minidev:json-smart Dependency in Jira Service Management Data CenterCVE-2023-13707.5 Wysoka