Fixes have been issued by Atlassian to address nearly 30 third-party flaws across its products, including the maximum severity XML external entity injection vulnerability in the open source content analysis toolkit Apache Tika, tracked as CVE-2025-66516, reports SecurityWeek.Attacks leveraging CVE-2025-66516, which was discovered within Tika's core, PDF, and parser modules and impacts Atlassian's Confluence, Bamboo, Crowd, Fisheye/Crucible, Jira, and Jira Service Management offerings, could prompt information disclosure, server-side request forgery attacks, denial-of-service, and remote code execution.Atlassian has also updated Confluence and Jira/Jira Service Management to patch a critical prototype pollution bug in webpack loader-utils, tracked as CVE-2022-37601, and another critical prototype pollution weakness in the ZRender library, tracked as CVE-2021-39227, respectively. More than 24 other high-severity XXE, DoS, SSRF, RCE, prototype pollution, improper authorization, file inclusion, and improper authorization bugs have been resolved by Atlassian.
Vulnerability Management, Patch/Configuration Management
Maximum severity Apache Tika bug, others fixed by Atlassian

(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



