PT-2024-2730 · Atlassian+5 · Confluence Data Center/Server+9

Yakov Shafranovich

·

Published

2024-02-19

·

Updated

2026-05-18

·

CVE-2024-25710

CVSS v3.1

8.1

High

VectorAV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Commons Compress versions 1.3 through 1.25.0 Bamboo Data Center and Server versions 9.0.0, 9.1.0, 9.2.1, 9.3.0, 9.4.0, and 9.5.0 Confluence Data Center and Server version 7.14
Description The issue is related to a Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress. This vulnerability may allow an unauthenticated attacker to expose assets in the environment, susceptible to exploitation, with high impact to confidentiality, integrity, and availability. The vulnerability requires no user interaction.
Recommendations Apache Commons Compress versions 1.3 through 1.25.0: Upgrade to version 1.26.0. Bamboo Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.12. Bamboo Data Center and Server 9.4: Upgrade to a release greater than or equal to 9.4.4. Bamboo Data Center and Server 9.5: Upgrade to a release greater than or equal to 9.5.2. Confluence Data Center and Server 7.19: Upgrade to a release greater than or equal to 7.19.25. Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.12. Confluence Data Center and Server 8.9: Upgrade to a release greater than or equal to 8.9.4.

Fix

Infinite Loop

Weakness Enumeration

Related Identifiers

AZL-34812
AZL-43564
AZL-44916
BDU:2024-02851
CLEANSTART-2026-IA43044
CLEANSTART-2026-SQ91016
CLEANSTART-2026-WK99982
CVE-2024-25710
GHSA-4G9R-VXHX-9PGX
OPENSUSE-SU-2024:13702-1
SUSE-SU-2024:0726-1
SUSE-SU-2024_0726-1

Affected Products

Apache Commons Compress
Astra Linux
Bamboo
Bamboo Data Center/Server
Bitbucket
Confluence
Confluence Data Center/Server
Debian
Red Os
Suse