Vulnerability Management, Patch/Configuration Management

Maximum severity Apache Tika bug, others fixed by Atlassian

Homepage of atlassian website on the display of PC, url - atlassian.com.

Fixes have been issued by Atlassian to address nearly 30 third-party flaws across its products, including the maximum severity XML external entity injection vulnerability in the open source content analysis toolkit Apache Tika, tracked as CVE-2025-66516, reports SecurityWeek.

Attacks leveraging CVE-2025-66516, which was discovered within Tika's core, PDF, and parser modules and impacts Atlassian's Confluence, Bamboo, Crowd, Fisheye/Crucible, Jira, and Jira Service Management offerings, could prompt information disclosure, server-side request forgery attacks, denial-of-service, and remote code execution.

Atlassian has also updated Confluence and Jira/Jira Service Management to patch a critical prototype pollution bug in webpack loader-utils, tracked as CVE-2022-37601, and another critical prototype pollution weakness in the ZRender library, tracked as CVE-2021-39227, respectively. More than 24 other high-severity XXE, DoS, SSRF, RCE, prototype pollution, improper authorization, file inclusion, and improper authorization bugs have been resolved by Atlassian.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds