Atlassian disclosed two high-severity cryptographic failures in Bamboo Data Center tied to vulnerable Bouncy Castle for Java components, affecting versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0. The advisories say an unauthenticated attacker could exploit the flaws without user interaction, potentially exposing assets in the environment and causing high confidentiality impact. Atlassian assigned both issues a CVSS 4.0 score of 8.7 and said the defects do not directly affect integrity or availability.
One issue involves org.bouncycastle:bcpkix-jdk18on, where CMS AuthenticatedData content is not properly bound to the MAC when authAttrs are present in Bouncy Castle versions before 1.85; the other affects org.bouncycastle:bcprov-jdk18on, where KCCMBlockCipher fails to bind the nonce when AAD is absent, enabling cross-nonce AEAD forgery. Atlassian directed customers to upgrade to the latest Bamboo Data Center release or, at minimum, move to fixed supported versions 10.2.22 or 12.1.10 and later; Atlassian’s release documentation identifies Bamboo 12.1 as the current long-term support line with 12.1.7 previously listed as the latest bug-fix release.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Atlassian disclosed a second high-severity cryptographic failure in Bamboo Data Center tied to the org.bouncycastle:bcprov-jdk18on dependency, affecting the same Bamboo versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0. The advisory says the flaw can be exploited by an unauthenticated attacker without user interaction and recommends upgrading to the latest release or to 10.2.22+ and 12.1.10+.
Atlassian disclosed a high-severity cryptographic failure in Bamboo Data Center tied to the org.bouncycastle:bcpkix-jdk18on dependency, affecting versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0. Atlassian rated the issue CVSS 4.0 8.7 and advised customers to upgrade, or at minimum move to fixed supported versions 10.2.22+ or 12.1.10+.
Atlassian's Bamboo release notes page documents product releases, bug-fix versions, long-term support tracks, and links to historical Bamboo security advisories, including advisories dating from 2008 through 2021. The page also identifies Bamboo 12.1 as the latest release and 12.1.7 as the latest bug-fix release on the page.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
jira.atlassian.com
Open sourcejira.atlassian.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.