{"id":3782,"date":"2022-12-30T11:25:06","date_gmt":"2022-12-30T11:25:06","guid":{"rendered":"https:\/\/gitprotect.io\/blog\/?p=3782"},"modified":"2024-02-28T08:41:06","modified_gmt":"2024-02-28T08:41:06","slug":"2022-in-a-nutshell-atlassian-outages-and-vulnerabilities","status":"publish","type":"post","link":"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/","title":{"rendered":"2022 In A Nutshell: Atlassian Outages And Vulnerabilities"},"content":{"rendered":"\n<p>The Year 2022 definitely wasn&#8217;t the best year for Jira and Bitbucket users in history. Atlassian outages, warnings about data breaches, being on the first lines of media are all about Atlassian this year. So, let\u2019s analyze Atlassian Status and different media alerts to see what really happened to this giant cloud service provider.&nbsp;<\/p>\n\n\n\n<!--more-->\n\n\n\n<p class=\"has-background has-medium-font-size\" style=\"background-color:#fafafa\">December 2022<br><strong>Atlassian Status for Jira:<\/strong> 2 incidents<br><strong>Atlassian status for Bitbucket:<\/strong> 3 incidents<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Security flaw noticed in Atlassian can lead to taking over hundreds of Jira accounts<\/h2>\n\n\n\n<p>The researchers from CloudSEK noticed a vulnerable flaw in such Atlassian products as Jira, Confluence, and Bitbucket. They stated that threat actors can use this flaw to take over a company\u2019s Jira account. The problem was hidden in cookies which were invalidated, even if the user changed the password, with 2FA enabled. According to those security researchers the reason hid in the cookie validity, which is 30 days, as they only expire at the moment when the user logs out, or after 30 days.&nbsp;<\/p>\n\n\n\n<p>At the same time, <a href=\"https:\/\/community.atlassian.com\/t5\/Trust-Security-articles\/Atlassian-response-to-claims-regarding-session-tokens-cookies\/ba-p\/2217925\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Atlassian security team<\/a> had its own investigation into unauthorized access of a customer\u2019s Cloud account, which took place in December and triggered the buzz in the network. As it turned out during the investigation, it was an isolated case caused by malware on the customer\u2019s computer: \u201cThis incident was in no way caused by a vulnerability in Atlassian products or a compromise of Atlassian systems.\u201d&nbsp;<\/p>\n\n\n\n<p>For those Cloud customers who have some concerns about the security of their tokens, the Atlassian team recommended \u201creset their passwords, which will automatically log users out of all active and current sessions.\u201d<\/p>\n\n\n\n<p><a href=\"https:\/\/status.atlassian.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Atlassian Status<\/a> | <a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/security-flaw-in-atlassian-products-affecting-multiple-companies\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Dark Reading<\/a>&nbsp;<\/p>\n\n\n\n<p class=\"has-background has-medium-font-size\" style=\"background-color:#fafafa\">November 2022<br><strong>Atlassian Status for Jira:<\/strong> 4 incidents<br><strong>Atlassian status for Bitbucket:<\/strong> 4 incidents<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Atlassian remediates its critical vulnerabilities (9 out of 10!)<\/h2>\n\n\n\n<p>After noticing critical security vulnerabilities that the Atlassian characterized as 9 out of 10 in severity rating, the cloud service provider released some updates to address those problems in its centralized identity management platform &#8211; Crowd Server and Data Center, as well as git-based code and CI\/CD tool &#8211; Bitbucket Server and Data Center.&nbsp;<\/p>\n\n\n\n<p>According to Atlassian, is the command injection flaw, tracked as CVE-2022-43781, which affects Bitbucket Server and Data Center, and could permit the attacker with permission to control their username to gain code execution on the target system. Another flaw, CVE-2022-43782, which affected Crowd Server and Data Center, was a misconfiguration that cloud give an attacker a possibility to bypass password checks during the authentication as the Crown app and to call privileged API endpoints.&nbsp;<\/p>\n\n\n\n<p>Atlassian security advisory presented a step-by-step guidance for administrators to check if their products were compromised and what actions to take in that case.&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/atlassian-fixes-critical-command-injection-bug-in-bitbucket-server\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Bleeping Computer<\/a><\/p>\n\n\n\n<p class=\"has-background has-medium-font-size\" style=\"background-color:#fafafa\">October<br><strong>Atlassian Status for Jira:<\/strong> 1 incident<br><strong>Atlassian status for Bitbucket:<\/strong> 1 incident<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Two vulnerabilities noticed in Atlassian Jira could let an attacker steal account credentials<\/h2>\n\n\n\n<p>In October Bishop Fox, a cybersecurity services firm issued an advisory about two vulnerabilities they noticed in Atlassian Jira Align which allowed a user, who had an access to the service to easily gain access as an application administrator and, consequently, make an attack on the Atlassian service.&nbsp;<\/p>\n\n\n\n<p>Those two vulnerabilities were Server-Side Forgery (SSRF), tracked as CVE-2022-36802, and Insufficient Authorization Controls, tracked as CVE-2022-36802. The first one allowed the threat actor to get the AWS credentials to the Atlassian Jira service account and then access the <a href=\"https:\/\/gitprotect.io\/blog\/atlassian-cloud-shared-responsibility-model-are-you-aware-of-your-duties\/\" target=\"_blank\" rel=\"noreferrer noopener\">Atlassian Cloud<\/a> infrastructure as a user of Jira Align, The second one permitted those users who had People role permission to upgrade their and any user\u2019s role up to Super Admin. With this role, a user gained control over any settings in the Jira Align tenant, allowing him to modify Jira connections or security settings, reset user accounts.\u00a0<\/p>\n\n\n\n<p>&nbsp;<a href=\"https:\/\/bishopfox.com\/blog\/jira-align-advisory\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Jira<\/a> | <a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/atlassian-vulnerabilities-highlight-criticality-cloud-services\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Dark Reading<\/a><\/p>\n\n\n\n<p class=\"has-background has-medium-font-size\" style=\"background-color:#fafafa\">September<br><strong>Atlassian Status for Jira:<\/strong> 8 incidents<br><strong>Atlassian status for Bitbucket:<\/strong> 4 incidents<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Bitbucket suffers two outages in a month<\/h2>\n\n\n\n<p>In September Atlassian experienced two partial outages. The first one took place on September 8th and lasted for about an hour. As the Atlassian team posted later on <a href=\"https:\/\/bitbucket.status.atlassian.com\/incidents\/4fz2ny1nwtq8\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Atlassian Status <\/a>\u201cwe experienced requests timing for some of our customers for Atlassian Bitbucket. The issue has been resolved and the service is operating normally.\u201d<\/p>\n\n\n\n<p>The other outage happened later on September 25th and lasted much longer than the previous one &#8211; 7 hours and 33 minutes. According to <a href=\"https:\/\/bitbucket.status.atlassian.com\/incidents\/3308g2hlkfsx\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Attlassian<\/a> some customers \u201cusing <a href=\"https:\/\/gitprotect.io\/blog\/3-best-methods-to-back-up-and-restore-repositories-and-metadata-in-bitbucket-cloud\/\" target=\"_blank\" rel=\"noreferrer noopener\">Bitbucket Cloud<\/a> were unable to access their repositories.\u201d As it turned out this incident was triggered due to the storage vendor\u2019s outage (that Atlassian uses at their data center) caused by a firmware upgrade. However, the Atlassian team detected the incident within 14 minutes, it took hours to resolve the problem.\u00a0\u00a0<\/p>\n\n\n\n<p><a href=\"https:\/\/bitbucket.status.atlassian.com\/history?page=2\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Atlassian Status<\/a><\/p>\n\n\n\n<p class=\"has-background has-medium-font-size\" style=\"background-color:#fafafa\">August<br><strong>Atlassian Status for Jira:<\/strong> 5 incidents<br><strong>Atlassian status for Bitbucket:<\/strong> 2 incidents<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Atlassian warns its Bitbucket Server and Data Center users about another RCE vulnerability (9.9\/10)<\/h2>\n\n\n\n<p>There was another security advisory warning issued by the Atlassian, yet for Bitbucket Server and Data Center users. They tracked a vulnerability, aka CVE-2022-360804 &#8211; a security flaw, which received a CVSS severity score of 9.9 out of 10 and needed to be patched immediately. Using this critical vulnerability a threat actor could leverage to execute arbitrary code on vulnerable instances (according to Atlassian this vulnerable security flaw affected all Bitbucket and Data Center versions over 6.10.17, as well as from&nbsp; 7.0.0 to 8.3.0).<\/p>\n\n\n\n<p>Here is the Atlassian advisory commented on the issue: \u201cAn attacker with access to a public repository or with read permissions to a private Bitbucket repository can execute arbitrary code by sending a malicious HTTP request.\u201d Thus, to solve the problem the Atlassian had nothing but applying the available security update or some other mitigations immediately. Remote code execution (RCE) is the most potent of all vulnerability types, enabling crooks to do extensive damage while bypassing security measures, so this motive should be considered here.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/atlassian-bitbucket-server-vulnerable-to-critical-rce-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Bleeping Computer<\/a><\/p>\n\n\n\n<p class=\"has-background has-medium-font-size\" style=\"background-color:#fafafa\">July<br><strong>Atlassian Status for Jira:<\/strong> 9 incidents<br><strong>Atlassian Status for Bitbucket:<\/strong> 5 incidents<\/p>\n\n\n\n<p class=\"has-background has-medium-font-size\" style=\"background-color:#fafafa\">June<br><strong>Atlassian Status for Jira:<\/strong> 3 incidents<br><strong>Atlassian status for Bitbucket:<\/strong> 9 incidents<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">SSRF flaw tracked in Jira could lead to leaked sensitive credentials<\/h2>\n\n\n\n<p>Researchers from <a href=\"https:\/\/blog.assetnote.io\/2022\/06\/26\/exploiting-ssrf-in-jira\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Assetnote<\/a> tracked a server-side request forgery (SSRF), tracked as CVE-2022-26135, in Jira and Jira Service Management. This vulnerability permitted the attackers \u201cto make requests to arbitrary URLs, with any HTTP method, header and body.\u201d<\/p>\n\n\n\n<p>Later Atlassian explained in its <a href=\"https:\/\/confluence.atlassian.com\/jira\/jira-server-security-advisory-29nd-june-2022-1142430667.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">security advisory<\/a>: \u201cDepending on the environment the Jira instance is deployed in, the impact of this bug varies. For example, when deployed in AWS, it could leak sensitive credentials.\u201d To solve the issue Atlassian suggested the users, who didn\u2019t have their Jira site accessed via the atlassian.net domain, to update their Jira app, as they could be affected by the mentioned vulnerability.&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/portswigger.net\/daily-swig\/atlassian-patches-full-read-ssrf-in-jira\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">The Daily Swig<\/a><\/p>\n\n\n\n<p class=\"has-background has-medium-font-size\" style=\"background-color:#fafafa\">May<br><strong>Atlassian Status for Jira:<\/strong> 5 incidents<br><strong>Atlassian status for Bitbucket:<\/strong> 5 incidents<\/p>\n\n\n\n<p class=\"has-background has-medium-font-size\" style=\"background-color:#fafafa\">April<br><strong>Atlassian Status for Jira:<\/strong> 2 incidents<br><strong>Atlassian status for Bitbucket:<\/strong> 2 incidents<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">An all-time Jira outage affects 775 customers and lasts for almost two weeks<\/h2>\n\n\n\n<p>About 775 Jira customers couldn\u2019t access their data for almost two weeks, from April 5th to April 18th. To make a long story short &#8211; the reason behind it was a maintenance script that accidentally wiped hundreds of customer sites due to communication issues between two Atlassian teams working on deactivating a legacy app. The team used the wrong execution mode and wrong list of IDs.&nbsp;<\/p>\n\n\n\n<p>As a consequence, this human mistake led to catastrophic results for those who didn\u2019t have a backup plan in place. Once analyzed the data, the Atlassian managed to gather during the incident\u2019s investigation, Sri Viswanath, the Atlassian engineer, said \u201cThe result was an immediate deletion of 883 sites (representing 775 customers) between 07:38 UTC and 08:01 UTC on Tuesday, April 5th, 2022.\u201d&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/technology\/atlassian-doubles-the-number-of-orgs-affected-by-two-week-outage\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Bleeping Computer<\/a> I <a href=\"https:\/\/gitprotect.io\/blog\/was-the-jira-outage-the-last-atlassian-problem\/\" target=\"_blank\" rel=\"noreferrer noopener\">GitProtect.io blog<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">A detected vulnerability found in Jira could permit an attacker bypass authentication to customer\u2019s account<\/h2>\n\n\n\n<p>Another incident that\u2019s worth our attention is Atlassian&#8217;s announcement about the critical vulnerability which affected Jira.They noticed the security flaw, later identified as CVE-2022-0540, which was aimed at Seraph, the web authentication framework of Jira and Jira Service Management.&nbsp; Exploiting this vulnerability the threat actor could bypass authentication and authorization using specially crafted HTTP requests.&nbsp;<\/p>\n\n\n\n<p>Atlassian issued a statement: \u201cAlthough the vulnerability is in the core of Jira, it affects first and third-party apps that specify roles required at the WebWork1 action namespace level and do not specify it at an action level.\u201d<\/p>\n\n\n\n<p>In a nutshell: this security flaw can bypass the authentication and authorization requirements in WebWork actions where a vulnerable configuration is used, yet the threat actor can only do it if no other authentication or authorization checks are used.&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/www.securityweek.com\/atlassian-patches-critical-authentication-bypass-vulnerability-jira\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Security Week<\/a><\/p>\n\n\n\n<p class=\"has-background has-medium-font-size\" style=\"background-color:#fafafa\">March<br><strong>Atlassian Status for Jira:<\/strong> 5 incidents<br><strong>Atlassian status for Bitbucket:<\/strong> 3 incidents<\/p>\n\n\n\n<p class=\"has-background has-medium-font-size\" style=\"background-color:#fafafa\">February<br><strong>Atlassian Status for Jira:<\/strong> 1 incident<br><strong>Atlassian status for Bitbucket:<\/strong> 4 incidents<\/p>\n\n\n\n<p class=\"has-background has-medium-font-size\" style=\"background-color:#fafafa\">January<br><strong>Atlassian Status for Jira:<\/strong> 3 incidents<br><strong>Atlassian status for Bitbucket:<\/strong> 3 incidents<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator has-css-opacity\"\/>\n\n\n\n<p class=\"has-text-align-left\" style=\"font-size:22px\">Are you switching to a DevSecOps operation model? Remember to <strong>secure your code with the first professional GitHub, Bitbucket, GitLab, and Jira backup<\/strong>.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button align=&quot;center&quot;\"><a class=\"wp-block-button__link has-background wp-element-button\" href=\"https:\/\/gitprotect.io\/sign-up.html\" style=\"border-radius:50px;background-color:#ff0300\" target=\"_blank\" rel=\"noreferrer noopener\">Start 14 days free GitProtect trial<\/a><\/div>\n<\/div>\n\n\n\n<hr class=\"wp-block-separator has-css-opacity\"\/>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">What to do in 2023?<\/h2>\n\n\n\n<p>Atlassian outages, vulnerabilities &#8211; all of that tickled the nerves of Jira and Bitbucket users in 2022. We have counted 41 incidents in Bitbucket and 53 incidents in Jira mentioned in Atlassian Status. About 11 hours Atlassian Bitbucket users were out of the service or partially out, while Jira users experienced about a staggering 329 hours of outage.&nbsp;<\/p>\n\n\n\n<p>Unfortunately, it is impossible to avoid situations like that. All we can do is to be ready to respond to the challenges of security by building a data protection strategy. It should include among others, security of credentials, secret scanning and backup.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Security of credentials&nbsp;<\/h3>\n\n\n\n<p>It is a well-known fact that credentials, passwords, and authentication tokens you should keep in a secure place. Password Managers are a good option that eliminates the keyloggers risks. Security experts advise to be creative when making up new passwords, create unique, abstract ones, use letters of both upper- and lower-cases, numbers, signs &#8211; everything that can make your passwords unique and non-repeated. And\u2026 don\u2019t forget about changing your passwords at least every three months.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Two-factor authentication<\/h3>\n\n\n\n<p>Another important aspect of your credential protection is 2FA. When you have your 2FA turned on, nobody can access your account without your notice and approval from another source or piece of information. The most popular way is to approve the authentication with the mobile phone &#8211; both by SMS codes or applications. However, it\u2019s worth considering a hardware key.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Secret scanning<\/h3>\n\n\n\n<p>When your team of developers collaborates on building the code, some sensitive information, like passwords, API keys, authentication tokens and other secrets can be accidentally added to your repositories. To protect your sensitive data use secret scanning which will track if any sensitive data can potentially be exposed and trigger notifications if the leaked secrets are detected within commits.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Backup&nbsp;<\/h3>\n\n\n\n<p>Outages happen due to many reasons: hacker attacks, hardware or software failures, human mistakes &#8211; the trigger of \u201chistorical\u201d Atlassian outage in April. However, you can try to take proactive measures and backup your environment, which will permit you to reduce the impact of the downtime by running your backup copy and continuing your work without interruption. Those Jira users who had <a href=\"https:\/\/gitprotect.io\/jira-backup.html\" target=\"_blank\" rel=\"noreferrer noopener\">Jira backup<\/a> in place, and ran it during the April Atlassian outage managed to continue their working process without financial or data losses.&nbsp;<\/p>\n\n\n\n<p class=\"has-background\" style=\"background-color:#fafafa\">Not only Atlassian encountered some serious issues and vulnerabilities&#8230; <a href=\"https:\/\/gitprotect.io\/blog\/ultimate-review-of-github-related-fackups-in-2022\/\" target=\"_blank\" rel=\"noreferrer noopener\">GitHub security incidents<\/a> that have happened in 2022 &#8211;  check the summary.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Useful resources:<\/h2>\n\n\n\n<p class=\"has-background\" style=\"background-color:#f4fafe\"><strong>E-books<\/strong><br><a href=\"https:\/\/gitprotect.io\/ci-cd-guide.html\" target=\"_blank\" rel=\"noreferrer noopener\">The DevOps Guide to Backup in CI\/CD<\/a><br><a href=\"https:\/\/gitprotect.io\/git-backup-guide.html\" target=\"_blank\" rel=\"noreferrer noopener\">Git Backup Guide<\/a><br><br><strong>Cheat Sheet<\/strong><br><a href=\"https:\/\/gitprotect.io\/docs\/bitbucket-cheat-sheet.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Bitbucket Backup Cheat Sheet<\/a><br><a href=\"https:\/\/gitprotect.io\/docs\/jira-cheat-sheet.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Jira Backup Cheat Sheet<\/a><br><br><strong>Blog posts<\/strong><br><a href=\"https:\/\/gitprotect.io\/blog\/jira-backup-best-practices\/\" target=\"_blank\" rel=\"noreferrer noopener\">Jira Backup Best Practices<\/a><br><a href=\"https:\/\/gitprotect.io\/blog\/bitbucket-backup-best-practices\/\" target=\"_blank\" rel=\"noreferrer noopener\">Bitbucket Backup Best Practices<\/a><br><a href=\"https:\/\/gitprotect.io\/blog\/bitbucket-backup-strategies-backup-and-data-recovery-for-bitbucket\/\" target=\"_blank\" rel=\"noreferrer noopener\">Bitbucket Backup Strategies &#8211; Backup and Data Recovery for Bitbucket<\/a><br><a href=\"https:\/\/gitprotect.io\/blog\/bitbucket-zero-downtime-backup-how-to-backup-bitbucket-data-without-downtime\/\" target=\"_blank\" rel=\"noreferrer noopener\">Bitbucket Zero Downtime Backup &#8211; How to Backup Bitbucket Data Without Downtime<\/a><br><a href=\"https:\/\/gitprotect.io\/blog\/why-backup-jira-is-there-any-risk-of-data-loss\/\" target=\"_blank\" rel=\"noreferrer noopener\">Why backup Jira &#8211; Is there Any Risk of Data Loss?<\/a><br><a href=\"https:\/\/gitprotect.io\/blog\/pro-security-tips-for-jira-admins\/\" target=\"_blank\" rel=\"noreferrer noopener\">PRO Security Tips for Jira Admins<\/a><br><br><strong>Videos<\/strong><br><a href=\"https:\/\/www.youtube.com\/channel\/UCiEnl6n0mIO6w7twccz-l2w?app=desktop\" target=\"_blank\" rel=\"noreferrer noopener\">GitProtect Academy<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Year 2022 definitely wasn&#8217;t the best year for Jira and Bitbucket users in history. Atlassian outages, warnings about data breaches, being on the first lines of media are all about Atlassian this year. So, let\u2019s analyze Atlassian Status and different media alerts to see what really happened to this giant cloud service provider.&nbsp;<\/p>\n","protected":false},"author":8,"featured_media":3785,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,73],"tags":[],"class_list":["post-3782","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bitbucket","category-jira","post--single"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>2022 In A Nutshell: Atlassian Outages And Vulnerabilities - Blog | GitProtect.io<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"2022 In A Nutshell: Atlassian Outages And Vulnerabilities - Blog | GitProtect.io\" \/>\n<meta property=\"og:description\" content=\"The Year 2022 definitely wasn&#8217;t the best year for Jira and Bitbucket users in history. Atlassian outages, warnings about data breaches, being on the first lines of media are all about Atlassian this year. So, let\u2019s analyze Atlassian Status and different media alerts to see what really happened to this giant cloud service provider.&nbsp;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog | GitProtect.io\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/XoperoSoftware\/\" \/>\n<meta property=\"article:published_time\" content=\"2022-12-30T11:25:06+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-02-28T08:41:06+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/gitprotect.io\/blog\/wp-content\/uploads\/2022\/12\/bitbucket_on_fire.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"600\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Daria Kulikova, Content Writer at GitProtect.io\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@GitProtectio\" \/>\n<meta name=\"twitter:site\" content=\"@GitProtectio\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Daria Kulikova, Content Writer at GitProtect.io\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/\"},\"author\":{\"name\":\"Daria Kulikova, Content Writer at GitProtect.io\",\"@id\":\"https:\/\/gitprotect.io\/blog\/#\/schema\/person\/6618fde5a7cf7e327fefa4f0035466d3\"},\"headline\":\"2022 In A Nutshell: Atlassian Outages And Vulnerabilities\",\"datePublished\":\"2022-12-30T11:25:06+00:00\",\"dateModified\":\"2024-02-28T08:41:06+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/\"},\"wordCount\":1994,\"publisher\":{\"@id\":\"https:\/\/gitprotect.io\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/gitprotect.io\/blog\/wp-content\/uploads\/2022\/12\/bitbucket_on_fire.png\",\"articleSection\":[\"Bitbucket\",\"Jira\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/\",\"url\":\"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/\",\"name\":\"2022 In A Nutshell: Atlassian Outages And Vulnerabilities - Blog | GitProtect.io\",\"isPartOf\":{\"@id\":\"https:\/\/gitprotect.io\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/gitprotect.io\/blog\/wp-content\/uploads\/2022\/12\/bitbucket_on_fire.png\",\"datePublished\":\"2022-12-30T11:25:06+00:00\",\"dateModified\":\"2024-02-28T08:41:06+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/#primaryimage\",\"url\":\"https:\/\/gitprotect.io\/blog\/wp-content\/uploads\/2022\/12\/bitbucket_on_fire.png\",\"contentUrl\":\"https:\/\/gitprotect.io\/blog\/wp-content\/uploads\/2022\/12\/bitbucket_on_fire.png\",\"width\":1200,\"height\":600},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Strona g\u0142\u00f3wna\",\"item\":\"https:\/\/gitprotect.io\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"2022 In A Nutshell: Atlassian Outages And Vulnerabilities\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/gitprotect.io\/blog\/#website\",\"url\":\"https:\/\/gitprotect.io\/blog\/\",\"name\":\"GitProtect.io Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/gitprotect.io\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/gitprotect.io\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/gitprotect.io\/blog\/#organization\",\"name\":\"GitProtect.io\",\"url\":\"https:\/\/gitprotect.io\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/gitprotect.io\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/gitprotect.io\/blog\/wp-content\/uploads\/2023\/05\/favicon-528x528-1.png\",\"contentUrl\":\"https:\/\/gitprotect.io\/blog\/wp-content\/uploads\/2023\/05\/favicon-528x528-1.png\",\"width\":528,\"height\":528,\"caption\":\"GitProtect.io\"},\"image\":{\"@id\":\"https:\/\/gitprotect.io\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/XoperoSoftware\/\",\"https:\/\/x.com\/GitProtectio\",\"https:\/\/www.linkedin.com\/company\/xopero-software\/\",\"https:\/\/www.youtube.com\/channel\/UCiEnl6n0mIO6w7twccz-l2w\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/gitprotect.io\/blog\/#\/schema\/person\/6618fde5a7cf7e327fefa4f0035466d3\",\"name\":\"Daria Kulikova, Content Writer at GitProtect.io\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/gitprotect.io\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/gitprotect.io\/blog\/wp-content\/uploads\/2024\/09\/daria-kulikova-content-writer-at-gitprotect.io_avatar-96x96.jpg\",\"contentUrl\":\"https:\/\/gitprotect.io\/blog\/wp-content\/uploads\/2024\/09\/daria-kulikova-content-writer-at-gitprotect.io_avatar-96x96.jpg\",\"caption\":\"Daria Kulikova, Content Writer at GitProtect.io\"},\"description\":\"Daria is a Content Specialist at GitProtect.io, who has a degree in linguistics and an extensive translation background in different areas, including technology, IT, economics, etc. She loves self-improvement, so when she is offline, it\u2019s easy to find her learning and expanding her knowledge in Cybersecurity, and DevSecOps.\",\"url\":\"https:\/\/gitprotect.io\/blog\/author\/daria-kulikova\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"2022 In A Nutshell: Atlassian Outages And Vulnerabilities - Blog | GitProtect.io","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/","og_locale":"en_US","og_type":"article","og_title":"2022 In A Nutshell: Atlassian Outages And Vulnerabilities - Blog | GitProtect.io","og_description":"The Year 2022 definitely wasn&#8217;t the best year for Jira and Bitbucket users in history. Atlassian outages, warnings about data breaches, being on the first lines of media are all about Atlassian this year. So, let\u2019s analyze Atlassian Status and different media alerts to see what really happened to this giant cloud service provider.&nbsp;","og_url":"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/","og_site_name":"Blog | GitProtect.io","article_publisher":"https:\/\/www.facebook.com\/XoperoSoftware\/","article_published_time":"2022-12-30T11:25:06+00:00","article_modified_time":"2024-02-28T08:41:06+00:00","og_image":[{"width":1200,"height":600,"url":"https:\/\/gitprotect.io\/blog\/wp-content\/uploads\/2022\/12\/bitbucket_on_fire.png","type":"image\/png"}],"author":"Daria Kulikova, Content Writer at GitProtect.io","twitter_card":"summary_large_image","twitter_creator":"@GitProtectio","twitter_site":"@GitProtectio","twitter_misc":{"Written by":"Daria Kulikova, Content Writer at GitProtect.io","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/#article","isPartOf":{"@id":"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/"},"author":{"name":"Daria Kulikova, Content Writer at GitProtect.io","@id":"https:\/\/gitprotect.io\/blog\/#\/schema\/person\/6618fde5a7cf7e327fefa4f0035466d3"},"headline":"2022 In A Nutshell: Atlassian Outages And Vulnerabilities","datePublished":"2022-12-30T11:25:06+00:00","dateModified":"2024-02-28T08:41:06+00:00","mainEntityOfPage":{"@id":"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/"},"wordCount":1994,"publisher":{"@id":"https:\/\/gitprotect.io\/blog\/#organization"},"image":{"@id":"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/#primaryimage"},"thumbnailUrl":"https:\/\/gitprotect.io\/blog\/wp-content\/uploads\/2022\/12\/bitbucket_on_fire.png","articleSection":["Bitbucket","Jira"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/","url":"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/","name":"2022 In A Nutshell: Atlassian Outages And Vulnerabilities - Blog | GitProtect.io","isPartOf":{"@id":"https:\/\/gitprotect.io\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/#primaryimage"},"image":{"@id":"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/#primaryimage"},"thumbnailUrl":"https:\/\/gitprotect.io\/blog\/wp-content\/uploads\/2022\/12\/bitbucket_on_fire.png","datePublished":"2022-12-30T11:25:06+00:00","dateModified":"2024-02-28T08:41:06+00:00","breadcrumb":{"@id":"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/#primaryimage","url":"https:\/\/gitprotect.io\/blog\/wp-content\/uploads\/2022\/12\/bitbucket_on_fire.png","contentUrl":"https:\/\/gitprotect.io\/blog\/wp-content\/uploads\/2022\/12\/bitbucket_on_fire.png","width":1200,"height":600},{"@type":"BreadcrumbList","@id":"https:\/\/gitprotect.io\/blog\/2022-in-a-nutshell-atlassian-outages-and-vulnerabilities\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Strona g\u0142\u00f3wna","item":"https:\/\/gitprotect.io\/blog\/"},{"@type":"ListItem","position":2,"name":"2022 In A Nutshell: Atlassian Outages And Vulnerabilities"}]},{"@type":"WebSite","@id":"https:\/\/gitprotect.io\/blog\/#website","url":"https:\/\/gitprotect.io\/blog\/","name":"GitProtect.io Blog","description":"","publisher":{"@id":"https:\/\/gitprotect.io\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/gitprotect.io\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/gitprotect.io\/blog\/#organization","name":"GitProtect.io","url":"https:\/\/gitprotect.io\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/gitprotect.io\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/gitprotect.io\/blog\/wp-content\/uploads\/2023\/05\/favicon-528x528-1.png","contentUrl":"https:\/\/gitprotect.io\/blog\/wp-content\/uploads\/2023\/05\/favicon-528x528-1.png","width":528,"height":528,"caption":"GitProtect.io"},"image":{"@id":"https:\/\/gitprotect.io\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/XoperoSoftware\/","https:\/\/x.com\/GitProtectio","https:\/\/www.linkedin.com\/company\/xopero-software\/","https:\/\/www.youtube.com\/channel\/UCiEnl6n0mIO6w7twccz-l2w"]},{"@type":"Person","@id":"https:\/\/gitprotect.io\/blog\/#\/schema\/person\/6618fde5a7cf7e327fefa4f0035466d3","name":"Daria Kulikova, Content Writer at GitProtect.io","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/gitprotect.io\/blog\/#\/schema\/person\/image\/","url":"https:\/\/gitprotect.io\/blog\/wp-content\/uploads\/2024\/09\/daria-kulikova-content-writer-at-gitprotect.io_avatar-96x96.jpg","contentUrl":"https:\/\/gitprotect.io\/blog\/wp-content\/uploads\/2024\/09\/daria-kulikova-content-writer-at-gitprotect.io_avatar-96x96.jpg","caption":"Daria Kulikova, Content Writer at GitProtect.io"},"description":"Daria is a Content Specialist at GitProtect.io, who has a degree in linguistics and an extensive translation background in different areas, including technology, IT, economics, etc. She loves self-improvement, so when she is offline, it\u2019s easy to find her learning and expanding her knowledge in Cybersecurity, and DevSecOps.","url":"https:\/\/gitprotect.io\/blog\/author\/daria-kulikova\/"}]}},"_links":{"self":[{"href":"https:\/\/gitprotect.io\/blog\/wp-json\/wp\/v2\/posts\/3782","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gitprotect.io\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gitprotect.io\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gitprotect.io\/blog\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/gitprotect.io\/blog\/wp-json\/wp\/v2\/comments?post=3782"}],"version-history":[{"count":5,"href":"https:\/\/gitprotect.io\/blog\/wp-json\/wp\/v2\/posts\/3782\/revisions"}],"predecessor-version":[{"id":4859,"href":"https:\/\/gitprotect.io\/blog\/wp-json\/wp\/v2\/posts\/3782\/revisions\/4859"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gitprotect.io\/blog\/wp-json\/wp\/v2\/media\/3785"}],"wp:attachment":[{"href":"https:\/\/gitprotect.io\/blog\/wp-json\/wp\/v2\/media?parent=3782"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gitprotect.io\/blog\/wp-json\/wp\/v2\/categories?post=3782"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gitprotect.io\/blog\/wp-json\/wp\/v2\/tags?post=3782"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}