-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 ##################################################### ## N C S C ~ B E V E I L I G I N G S A D V I E S ## ##################################################### Titel : Kwetsbaarheden verholpen in Atlassian producten Advisory ID : NCSC-2026-0325 Versie : 1.00 Kans : medium CVE ID : CVE-2021-44906, CVE-2022-3517, CVE-2023-45133, CVE-2025-14813, CVE-2026-0603, CVE-2026-2332, CVE-2026-3505, CVE-2026-4800, CVE-2026-6321, CVE-2026-6322, CVE-2026-10050, CVE-2026-12143, CVE-2026-12151, CVE-2026-12802, CVE-2026-12803, CVE-2026-12816, CVE-2026-13149, CVE-2026-13506, CVE-2026-13676, CVE-2026-14257, CVE-2026-14682, CVE-2026-16221, CVE-2026-18446, CVE-2026-21582, CVE-2026-24734, CVE-2026-25639, CVE-2026-27601, CVE-2026-27606, CVE-2026-29786, CVE-2026-40983, CVE-2026-40984, CVE-2026-41284, CVE-2026-41842, CVE-2026-41845, CVE-2026-41850, CVE-2026-41851, CVE-2026-41907, CVE-2026-42033, CVE-2026-42035, CVE-2026-42041, CVE-2026-42198, CVE-2026-42583, CVE-2026-42587, CVE-2026-43513, CVE-2026-44249, CVE-2026-44486, CVE-2026-44487, CVE-2026-44488, CVE-2026-44490, CVE-2026-44492, CVE-2026-44494, CVE-2026-44495, CVE-2026-44496, CVE-2026-45416, CVE-2026-45623, CVE-2026-46625, CVE-2026-47838, CVE-2026-48043, CVE-2026-48779, CVE-2026-48801, CVE-2026-50010, CVE-2026-53434, CVE-2026-54291, CVE-2026-54512, CVE-2026-54513, CVE-2026-55685, CVE-2026-55831, CVE-2026-55833, CVE-2026-56745, CVE-2026-56819, CVE-2026-58059, CVE-2026-58060, CVE-2026-59639, CVE-2026-59642, CVE-2026-59869, CVE-2026-59871, CVE-2026-59873, CVE-2026-59874, CVE-2026-59887, CVE-2026-59901, CVE-2026-67320, CVE-2026-69152, CVE-2026-69192 (Details over de kwetsbaarheden kunt u vinden op de Mitre website: https://cve.mitre.org/cve/) Schade : high Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Improper Neutralization of CRLF Sequences ('CRLF Injection') Heap-based Buffer Overflow Improper Neutralization of Delimiters Improper Verification of Cryptographic Signature Improper Validation of Integrity Check Value Missing Release of Memory after Effective Lifetime Inefficient Algorithmic Complexity Improper Handling of Highly Compressed Data (Data Amplification) Interpretation Conflict Incorrect Behavior Order: Authorization Before Parsing and Canonicalization Not Failing Securely ('Failing Open') Always-Incorrect Control Flow Implementation Uncontrolled Recursion Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') Allocation of Resources Without Limits or Throttling Missing Release of Resource after Effective Lifetime Out-of-bounds Write Memory Allocation with Excessive Size Value Use of Out-of-range Pointer Offset Loop with Unreachable Exit Condition ('Infinite Loop') Improper Update of Reference Count Improperly Controlled Modification of Dynamically- Determined Object Attributes Server-Side Request Forgery (SSRF) Improper Verification of Source of a Communication Channel Improper Validation of Specified Index, Position, or Offset in Input Improper Validation of Unsafe Equivalence in Input Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') Inefficient Regular Expression Complexity Incomplete List of Disallowed Inputs Use of a Broken or Risky Cryptographic Algorithm Reusing a Nonce, Key Pair in Encryption Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') Improper Control of Generation of Code ('Code Injection') Improper Neutralization of Special Elements used in a Command ('Command Injection') Improper Handling of Alternate Encoding Incorrect Implementation of Authentication Algorithm Improper Certificate Validation Improper Check for Unusual or Exceptional Conditions Improper Validation of Specified Type of Input Unchecked Input for Loop Condition Improper Link Resolution Before File Access ('Link Following') Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') Improper Handling of Case Sensitivity Insertion of Sensitive Information Into Sent Data Authentication Bypass by Alternate Name Unintended Proxy or Intermediary ('Confused Deputy') Excessive Platform Resource Consumption within a Loop Detection of Error Condition Without Action Deserialization of Untrusted Data Incorrect Type Conversion or Cast Access of Resource Using Incompatible Type ('Type Confusion') Incorrect Parsing of Numbers with Different Radices Uitgiftedatum : 20260824 Toepassing : Atlassian Bamboo Atlassian Bitbucket Atlassian Bitbucket Data Center Atlassian Confluence Atlassian Confluence Data Center Atlassian Crowd Data Center Atlassian Crucible Atlassian Fisheye Atlassian Jira Atlassian Jira Service Management Data Center Atlassian Jira Service Management Server Atlassian Jira Software Data Center Atlassian Jira Software Server Versie(s) : Platform(s) : Beschrijving Atlassian heeft kwetsbaarheden verholpen in diverse producten zoals Bamboo, Bitbucket, Confluence, Jira, Crowd en Fisheye. De kwetsbaarheden bevinden zich in diverse Third-Party producten waar eerder updates voor zijn verschenen. Atlassian heeft deze updates verwerkt in de eigen producten. Kwaadwillenden kunnen de kwetsbaarheden misbruiken om een Denial-of- Service te veroorzaken, willekeurige code uit te voeren middels het injecteren van scripts of malafide SQL-quieries en/of gegevens te manipuleren of toegang te krijgen tot gevoelige gegevens. Enkele kwetsbaarheden hebben van origine een hoge CVSS score van 9 of meer en zijn door de ontwikkelaars van het kwetsbare product aanvankelijk ingeschaald als 'kritiek'. Door de wijze waarop Atlassian gebruik maakt van deze Third-party modules, is direct misbruik van deze kwetsbaarheden onwaarschijnlijker, waardoor Atlassian de risico's van misbruik voor hun producten lager inschaalt. Echter, door de grote hoeveelheid verholpen kwetsbaarheden adviseert het NCSC wel om deze updates met voorrang in te zetten, met name op systemen die toegankelijk zijn vanaf publieke infrastructuur. Mogelijke oplossingen Atlassian heeft updates uitgebracht voor Bamboo, Bitbucket, Confluence, Jira, Crowd en Fisheye. Zie de bijgevoegde referenties voor meer informatie. Referenties: Reference https://confluence.atlassian.com/security/security-bulletin- august-18-2026-1821999768.html Vrijwaringsverklaring Door gebruik van deze security advisory gaat u akkoord met de navolgende voorwaarden. Ondanks dat het NCSC de grootst mogelijke zorg heeft betracht bij de samenstelling van dit beveiligingsadvies, kan het NCSC niet instaan voor de volledigheid, juistheid of (voortdurende) actualiteit van dit beveiligingsadvies. De informatie in dit beveiligingsadvies is uitsluitend bedoeld als algemene informatie voor professionele partijen. Aan de informatie in dit beveiligingsadvies kunnen geen rechten worden ontleend. Het NCSC en de Staat zijn niet aansprakelijk voor enige schade ten gevolge van het gebruik of de onmogelijkheid van het gebruik van dit beveiligingsadvies, waaronder begrepen schade ten gevolge van de onjuistheid of onvolledigheid van de informatie in dit beveiligingsadvies. Op dit beveiligingsadvies is Nederlands recht van toepassing. Alle geschillen in verband met en/of voortvloeiend uit dit beveiligingsadvies zullen worden voorgelegd aan de exclusief bevoegde rechter te Den Haag. Deze rechtskeuze geldt tevens voor de voorzieningenrechter in kort geding. -----BEGIN PGP SIGNATURE----- iQGzBAEBCgAdFiEEGSwziqblmmRNtImqgupWoL0ZhGEFAmqMFHsACgkQgupWoL0Z hGHhqwwA3ybPeTsiDT45B4asJZ8nhx22Zz3FUBvVRJ6FdNPuJUAyPqPMr+0VByRR pz6AVwafn7YB5vN41ePIaf+rsZU9V9H6AswObHAovhAZ3tZC4Dx89nd5mHw2kn/v R5jmKrR9RcpvHTe3NOoMP/wKgFu1hPv/OA8N7adELoRnRNz3+l9F1jjijp9Vyhf5 +CWvjALE3vAosXBxJ44d5YF+PUo6RgtK2N8yQYdxZ1kLmOdlym2EZd40BMHaYMZ5 57V/oa8kB2D4RkiJEYGB2HPWmYvXbkca6lGM1rBdMlMGJap6q6JQBx5bGI3B8Beu Oh7bgH9KRYDijw0gA28hAY3w9O9T/1Cq3OC7wJi6bvTYsW5K1RLULgG0DBpk59Am TNU9yOfpJpcrj+L8i+Ym/jPdFCELusJc8yESNe0NNKGQ13krtWSiE/RSJgnu9eR0 sjnF3ZRc7DnHMsfsgdDj2Z9lDDD1mNIWROkuyGU+RLjHo8woEQEWU8AdCkHH6DOB 6MTvEt6Z =nkvi -----END PGP SIGNATURE-----