Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Atlassian Patches Critical Apache Tika Flaw

Posted on December 15, 2025December 15, 2025 By CWS

Atlassian has rolled out patches for roughly 30 third-party vulnerabilities impacting its merchandise, together with critical-severity flaws.

The primary safety defect that stands out is CVE-2025-66516 (CVSS rating of 10/10), a critical-severity XML Exterior Entity (XXE) injection bug in Apache Tika.

Impacting the tika-core, tika-pdf-module, and tika-parsers modules of the common parser, the flaw was disclosed in early December.

It may be exploited by way of crafted XFA recordsdata positioned inside PDF recordsdata, probably resulting in info leaks, denial-of-service (DoS), SSRF assaults, or distant code execution (RCE).

Atlassian merchandise that use Tika embody Bamboo, Confluence, Crowd, Fisheye/Crucible, Jira, and Jira Service Administration. The corporate has launched fixes for all six.

The record of critical-severity points that Atlassian resolved this month additionally consists of CVE-2022-37601 (CVSS rating of 9.8), a prototype air pollution vulnerability in webpack loader-utils, which is utilized in Confluence.

One other important prototype air pollution bug was patched in Jira and Jira Service Administration. Tracked as CVE-2021-39227 (CVSS rating of 9.8), it impacts the light-weight graphic library ZRender.

Atlassian’s contemporary spherical of fixes additionally resolves over two dozen high-severity DoS, XXE, SSRF, file inclusion, prototype air pollution, improper authorization, info disclosure, improper enter validation, and RCE flaws.Commercial. Scroll to proceed studying.

Software program updates that repair these defects have been launched for Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, Jira, and Jira Service Administration information middle and server merchandise.

As a result of the weaknesses have been present in third-party dependencies, they affect all Atlassian merchandise that depend on them.

Customers are suggested to use the patches as quickly as potential. Extra info on the bugs and their fixes may be present in Atlassian’s December 2025 safety advisory.

Associated: Gladinet CentreStack Flaw Exploited to Hack Organizations

Associated: Latest GeoServer Vulnerability Exploited in Assaults

Associated: Notepad++ Patches Updater Flaw After Reviews of Visitors Hijacking

Associated: IBM Patches Over 100 Vulnerabilities

Security Week News Tags:Apache, Atlassian, Critical, Flaw, Patches, Tika

Post navigation

Previous Post: AI Pentesting Tool that Autonomously Checks for Code Vulnerabilities and Executes Real Exploits
Next Post: New Clickfix Attack Exploits finger.exe Tool to Trick Users into Execute Malicious Code

Related Posts

Zafran Security Raises $60 Million in Series C Funding Security Week News
Asheville Eye Associates Says 147,000 Impacted by Data Breach Security Week News
How TTP-based Defenses Outperform Traditional IoC Hunting Security Week News
HoundBytes Launches Automated Security Analyst Security Week News
American Airlines Subsidiary Envoy Air Hit by Oracle Hack Security Week News
Orange Belgium Data Breach Impacts 850,000 Customers Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • ZnDoor Malware Exploiting React2Shell Vulnerability to Compromise Network Devices
  • Featured Chrome Browser Extension Caught Intercepting Millions of Users’ AI Chats
  • New PCPcat Exploiting React2Shell Vulnerability to compromise 59,000+ Servers
  • Militant Groups Are Experimenting With AI, and the Risks Are Expected to Grow
  • xHunt APT Hackers Attacking Microsoft Exchange and IIS Web Servers to Deploy Custom Backdoors

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • ZnDoor Malware Exploiting React2Shell Vulnerability to Compromise Network Devices
  • Featured Chrome Browser Extension Caught Intercepting Millions of Users’ AI Chats
  • New PCPcat Exploiting React2Shell Vulnerability to compromise 59,000+ Servers
  • Militant Groups Are Experimenting With AI, and the Risks Are Expected to Grow
  • xHunt APT Hackers Attacking Microsoft Exchange and IIS Web Servers to Deploy Custom Backdoors

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark