Skip to finding
interesting · Edge

Unauthenticated callers can read known files from the web roots of eight Atlassian server products.

Affects

Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo and Crowd Data Center, plus Crucible and Fisheye; self-managed enterprise collaboration and development servers.

The traversal reaches specifically named files beneath the application web root without authentication across the affected self-managed products.

Detail and 3 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, October 6, 2026