I've recently migrated from Snyk Scan pipe to Bitbucket Dependency Scanner, but I'm running into an issue. I'm using script: - pipe: atlassian/bitbucket-dependency-scanner:0.5.0 variables: ...
Hi, Is there a way to access code insight report generated after bitbucket dependency scan? I want to upload this insights report to artifact so that i can access in the next steps in the pi...
Specific error message: Status: Downloaded newer image for bitbucketpipelines/bitbucket-dependency-scanner:0.1.4 time="2024-11-19T16:21:25Z" level=error msg="error waiting for ...
...nalyzer (2 seconds) [INFO] Finished False Positive Analyzer (0 seconds) [INFO] Finished NVD CVE Analyzer (0 seconds) [INFO] Finished Sonatype OSS Index Analyzer (0 seconds) [INFO] Finished V...
while im using the pipe bitbucket dependency scanner its getting failed.
...ffline file instead of Api key? Can i download an deprecated version and use the import/assset/cve folder or maby can i spoof the api key from NVD and point to a json file?
I'd like to know if Atlassian was impacted by any of these: CVE-2023-46805 (Authentication Bypass) in the web component of Ivanti ICS CVE-2024-21887 (Command Injection) for Ivanti Connect S...
Hi all I need to set up an nvd assets database. I'm using the cve import module, is there any possibility to use this solution ofline? I saw that in a previus version there was a ofline-m...
Take immediate action to protect your instance We have discovered that Confluence Data Center and Server customers on out-of-date versions including 8.4.5 are vulnerable to a remote code execution ...
...nstructions. CVE-2023-22524 - RCE Vulnerability in Atlassian Companion app for MacOS Confluence Data Center and Server (former and present customers) CVE-2023-22523 - RCE Vulnerability in A...
...mmediate action to protect their instances. Please carefully review all of the Critical Security Advisories impacting your Atlassian product(s) to verify affected versions and instructions. CVE-2023-2...
Atlassian has disclosed a CVE that impacts Bamboo Data Center and Bamboo Server today. This particular CVE affects all previous versions of Bamboo. Please see the full advisory in https://c...
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24998 https://nvd.nist.gov/vuln/detail/CVE-2023-24998 Still waiting for an "Official" response from Atlassian. We've found the l...
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23529
Our security scanning software is complaining about Apache Commons Text within our Confluence installation. When will Atlassian be posting guidance/remediation on this issue?
Does the reported vulnerability CVE-2022-36804 affect the confluence tool?
This advisory is a critical severity security vulnerability that was introduced in version 7.0.0 of Bitbucket Server and Data Center. All versions released after 6.10.17 including 7.0.0 and newer are...
Hi, as i can see in https://confluence.atlassian.com/security/multiple-products-security-advisory-cve-2022-26136-cve-2022-26137-1141493031.html our used jira & confluence versions are l...
What action should cloud customers (Confluence) need to take to keep corporate information secure? Is there any corrective action that customers need to take?
Hi , We are using a vunelrable jira server edition. 8.19.X for CVE-2022-26135 - Full-Read Server Side Request Forgery in Mobile Plugin for Jira Data Center and Server. But t...
Atlassian has published security advisory CVE-2022-0540 today, 29 June 2022. This advisory is in regards to and affects the Jira Server Mobile Plugin which is bundled with Jira and Jira S...
Good Afternoon, I have remediated CVE-2022-26134 with the temporary workaround in our stage environment for now and wanted to verify before doing the same to prod. Is there a script or a c...
Hello, We are using version 8.20.1 as jira server. However, we received a vulnerability notice today. CVE-2020-14179 we've done the readings for the issue here. I couldn't find such an open number o...
See: https://lists.apache.org/thread/6ckmjfb1k61dyzkto9vm2k5jvt4o7w7c Would be great to have an Atlassian response/FAQ page similar to this one.
Regarding the recently announced critical security advisory for CVE-2022-0540 regarding Authentication bypass in JIRA Server, is this still a critical vulnerability if the JIRA instance is confined t...
Copied to clipboard
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.