Tracking Atlassian Security Advisories

Tracking Atlassian Security Advisories


The Rundown

Due to the growing dependence of business operations on the Atlassian suite, the self-hosted Atlassian applications are becoming even more enticing targets for security breaches. A loss of data, a ransomware attack, a service outage, or a data breach could halt your business operations. It is important for all of us who manage self-hosted Atlassian products to stay vigilant of the risks to minimize these threats.


Subscribe to Atlassian Security Advisors

Atlassian publishes security advisories at Security Advisories | Atlassian

To be notified by email when new advisories are published go to Email and Privacy Preferences and subscribe to Tech Alerts emails. We also recommend signing up for the Atlassian Blog as well (at the top of the above link).


Stay Educated

CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws. Many websites track and diagnose CVEs like CVE or CVE Details. These websites can be used to learn how to diagnose and identify critical threats to your systems. Is the threat critical and must be patched right away? Who and what does this affect and what are the signs of a breach? These pieces of information could be important to stopping or identifying a threat.

Blue Ridge uses CVE Details to stay up to date on the latest threats. See an example here:

CVE-2020-4027


Keep the Atlassian Suite Up to Date

Atlassian has created Long Term Support releases for most of its applications. The LTS versions contain security-critical patches that could help protect your instances and Atlassian regularly updates these versions with security and bug patches. Try to avoid allowing your application installation versions from falling the current LTS version.


Move to Data Center or Cloud Now

Atlassian will no longer support or patch server products after February 15, 2024. If you are using a Server product, are you prepared to make the jump to Data Center or Cloud? You can learn more about which route to choose from our previous article: Cost Analysis of Atlassian Data Center vs Atlassian Cloud. If not, we strongly recommend you begin to plan such a migration to avoid zero-day attacks, especially ones occurring after the end of Server support.

Cost Analysis of Atlassian Data Center vs Atlassian Cloud


Engage the Experts

Are you having trouble upgrading to an LTS version or patching an Atlassian product? Are you not sure if Data Center or Cloud is a better choice for you? Do you need help with a migration? Engage our experts here: help@blueridge.cx

 

 

 

Looking for labels? They can now be found in the details panel on the floating action bar.