Advisory - Fisheye and Crucible - CVE-2017-16861

2018-02-08 Thread David Black
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 This email refers to the advisory found at https://confluence.atlassian.com/x/iPQyO and https://confluence.atlassian.com/x/h-QyO . CVE ID: * CVE-2017-16861. Product: Fisheye and Crucible. Affected Fisheye and Crucible product versions: version

August 2017 - SourceTree - Critical Security Advisory

2017-09-06 Thread David Black
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 This email refers to the advisory found at https://confluence.atlassian.com/x/c-mdNw . CVE ID: * CVE-2017-1000117 - Git. * CVE-2017-1000115 - Mercurial. * CVE-2017-1000116 - Mercurial. * CVE-2017-9800 - Subversion. Product: SourceTree. Affected

April 2017 - Confluence - Security Advisory

2017-04-26 Thread David Black
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 CVE ID: * CVE-2017-7415. Product: Confluence. Affected Confluence product versions: 6.0.0 <= version < 6.0.7 Fixed Confluence product versions: * for 6.0.x, Confluence 6.0.7 has been released with a fix for this issue. Summary: This advisor

Atlassian - March 2017 - Bamboo, Crowd and HipChat Server - Critical Security Advisory

2017-03-14 Thread David Black
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 This email refers to the following advisory pages: * Bamboo - https://confluence.atlassian.com/x/_slDN * Crowd - https://confluence.atlassian.com/x/PMpDN * HipChat Server - https://confluence.atlassian.com/x/lj1LN CVE ID: * CVE-2017-5638. Produ

October 2016 - Crowd - Critical Security Advisory

2016-10-31 Thread David Black
ncerns regarding this advisory, please raise a support request at https://support.atlassian.com/. - -- David Black / Security Engineer. -BEGIN PGP SIGNATURE- iQIcBAEBCgAGBQJYDWDNAAoJECQgl6K8Unag6OUP/R3+oXyZG9aBuvz1OxERT3z8 HqVcud728DaTnG/qm+72fQzptxr9O/jwWS

September 2016 - HipChat Plugin for various products - Critical Security Advisory

2016-10-05 Thread David Black
assian.com/display/AdminJIRA/JIRA+7.2.x+platform+release+notes. You can download the latest version of JIRA from the download centre found at https://www.atlassian.com/software/jira/download. Support: If you have questions or concerns regarding this advisory, please raise

July 2016 - Bamboo Server - Critical Security Advisory

2016-07-25 Thread David Black
oo/download. Support: If you have questions or concerns regarding this advisory, please raise a support request at https://support.atlassian.com/ . - -- David Black / Security Engineer. -BEGIN PGP SIGNATURE- Version: GnuPG v1 iQIcBAEBCgAGBQJXlrO3AAoJECQgl6K8UnaguiMP/Rri5vOtUQ4V/QC6uCBndguP

May 2016 - HipChat Server - Critical Security Advisory

2016-05-12 Thread David Black
his advisory, please raise a support request at https://support.atlassian.com/ . - -- David Black / Security Engineer. -BEGIN PGP SIGNATURE- Version: GnuPG v1 iQIcBAEBCgAGBQJXNWUWAAoJECQgl6K8Unag47IP/3KVjVhAUYD5Hdu8hWN2cwHF X/fyelKzGyXokiQK9TfKQ2K88oV8FLJnEgFGMxliwHZF0v8xj+EukHhf8axFZ

January 2016 - Bamboo - Critical Security Advisory

2016-01-21 Thread David Black
you have questions or concerns regarding this advisory, please raise a support request at https://support.atlassian.com/ . - -- David Black / Security Engineer. -BEGIN PGP SIGNATURE- Version: GnuPG v1 iQIcBAEBCgAGBQJWoWoKAAoJECQgl6K8UnagCpsP/0aqA3pOZvOWiW9VrwL2cpmL XoAqN5blfeM

CVE-2015-6576: Bamboo - Deserialisation resulting in remote code execution

2015-10-23 Thread David Black
tre found at https://www.atlassian.com/software/bamboo/download. Support: If you have questions or concerns regarding this advisory, please raise a support request at https://support.atlassian.com/ . -- David Black / Security Engineer.

CVE-2015-5603: JIRA and the HipChat For JIRA plugin - Velocity Template Injection

2015-09-02 Thread David Black
hen as a temporary workaround, you can disable or uninstall the HipChat For JIRA plugin in JIRA. Support: If you have questions or concerns regarding this advisory, please raise a support request at https://support.atlassian.com/ . -- David Black / Security Engineer.