How can we help?

Contact our Solutions team


Contact our Apps team


Click here to chat with our
support team now

What You Need to Know About Atlassian's Security Vulnerability Announcement
Gretchen Pawloski
Director, Product Marketing
Share this article

In today's day and age, it's nearly impossible to find anyone not concerned by or challenged with addressing cybersecurity issues. Cyberthreats continue grow in both volume and complexity. Over the past five years, security breaches have increased by 67%, according to Accenture’s global survey, as part of a $1.5 trillion industry (and growing).

As the scope and scale of cyber threats expand, it's important to remain vigilant and to surface any potential vulnerabilities as early as possible to protect against business catastrophe. In that spirit, Atlassian has recently announced critical severity security advisories for a number of its popular products that require swift and immediate attention, including:

  • Bitbucket Server & Bitbucket Data Center
  • Jira Server & Jira Data Center
  • Jira Service Desk & Jira Service Desk Data Center

In particular, the Bitbucket Server & Bitbucket Data Center alert concerns the products having an argument injection vulnerability, allowing an attacker to inject additional arguments into Git commands, which could lead to remote code execution. The Jira Server and Data Center warning addresses a server-side template injection vulnerability in Jira Server and Data Center, in the Jira Importers Plugin (JIM), that would allow an attacker with "JIRA Administrators" access to exploit this issue and remotely execute code on systems.

The last advisory for Jira Service Desk and Service Desk Data Center highlight that attackers can grant themselves access to Jira Service Desk projects that have the Anyone can email the service desk or raise a request in the portal setting enabled, which allows an attacker to view all issues within all Jira projects contained in the vulnerable instance.

You can read all the specifics about each vulnerability and appropriate fixes in the following links:

Maybe it's time for help with security

The recent advisories should serve as a reminder just how complex and time-consuming protecting a business against bad actors can be.

Even historically secure platforms like Atlassian aren't immune to attempted hacks, which means your team — and whatever resources are available to them — must be on high alert and prepared to track down and mitigate security vulnerabilities in literally every platform or system your organization uses.

While some teams may be prepared to make that commitment, the overwhelming majority of organizations simply can't afford to repurpose existing team members away from product and service delivery to handle security or staff up a full-time team to take on the challenge.

That's where Atlassian Solution Partners like ServiceRocket come in. Atlassian partners can assist with everything from licensing and initial configurations to continuous optimization and security updates to minimize the risk of a data breach. Some even have their own apps that integrate with Atlassian products to enhance the user experience.

Atlassian Solution Partners can help solidify plans and execute strategies around identity and permissions management, as well as install security patches and proactively monitor the environment for potential vulnerabilities.

One of the biggest advantages to entrusting your Atlassian security initiatives to a verified partner is the in-depth expertise and robust industry experience Partners offer. So they're able to implement security best practices in the background without impacting productivity or the user experience — all for a fraction of what it would cost if you tried to do it all internally.

Partnering with an Atlassian MSP can save you both time and money while ensuring security standards are in place and met. They can help mitigate risks and the financial implications of a security breach while helping teams better balance resources, including time and talent. Most of all, because of their extensive training and working knowledge of the software, Atlassian MSPs offer peace of mind and predictable expenses to their customers.


Learn more about how ServiceRocket's global team of Atlassian experts can improve the safety, security, and performance.

California Consumer Privacy Act (CCPA) Opt-Out Icon Notice at Collection