<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Fisheye (&lt; 4.9.15) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/fisheye--4.9.15/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 20:29:05 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/fisheye--4.9.15/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical Path Traversal in Atlassian Data Center Products (CVE-2026-21589)</title><link>https://feed.craftedsignal.io/briefs/2026-10-atlassian-path-traversal/</link><pubDate>Tue, 06 Oct 2026 20:29:05 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-atlassian-path-traversal/</guid><description>An unauthenticated arbitrary file read vulnerability (CVE-2026-21589) in multiple Atlassian Data Center products allows attackers to access sensitive configuration files via a path traversal flaw in the webresource router.</description><content:encoded><![CDATA[<p>CVE-2026-21589 is a critical vulnerability affecting a wide range of self-hosted Atlassian Data Center products, including Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, and Fisheye. The vulnerability arises from improper input validation within the <code>/download/*</code> webresource router. Specifically, the router performs a double URL-decode and utilizes an unescaping mechanism that converts <code>::</code> sequences into <code>/</code> characters. This behavior bypasses Tomcat's URI normalization, allowing unauthenticated attackers to perform path traversal and read arbitrary files relative to the web application root.</p>
<p>By targeting the <code>WEB-INF/</code> directory, attackers can extract sensitive files such as <code>web.xml</code>, <code>urlrewrite.xml</code>, and other configuration artifacts that may contain JDBC URLs, API tokens, and private keys. While directory listing is not possible, the predictability of Atlassian application file structures makes this vulnerability highly actionable. Active scanning and proof-of-concept exploits have been observed in the wild shortly after disclosure by watchTowr Labs.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker sends a specially crafted GET request to the <code>/download/resources/</code> endpoint.</li>
<li>The path includes a double URL-encoded traversal sequence (e.g., <code>..%3a%3a</code>) designed to survive initial Tomcat normalization.</li>
<li>The webresource router performs a secondary URL-decode on the URI.</li>
<li>The router's <code>unescapeSlashes</code> function converts the <code>::</code> sequence into a <code>/</code> path separator.</li>
<li>The application constructs a final path, resulting in a traversal sequence like <code>../../WEB-INF/web.xml</code>.</li>
<li>The <code>ServletContext.getResourceAsStream</code> function resolves the path relative to the application root without further security gating.</li>
<li>The application returns the contents of the requested sensitive configuration file in the HTTP response body.</li>
<li>Attacker harvests credentials or application metadata from the returned file for subsequent lateral movement.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows unauthenticated information disclosure of highly sensitive configuration data. Successful exploitation provides attackers with the necessary building blocks - such as database credentials and API keys - to compromise the underlying server infrastructure, escalate privileges, or facilitate lateral movement within the network. Multiple self-hosted product lines are affected, and active exploitation has been confirmed following the release of public exploit tooling.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for detection and mitigation:</p>
<ul>
<li>Upgrade all affected Atlassian Data Center and Server products to the fixed versions specified in the Atlassian September 2026 security advisory immediately.</li>
<li>Implement a WAF or reverse-proxy rule to block all incoming requests containing <code>%3a%3a</code> or <code>::</code> character sequences in the URL path.</li>
<li>Deploy the specific Tomcat RewriteValve or <code>urlrewrite.xml</code> mitigation rules provided by Atlassian for instances where immediate patching is not feasible.</li>
<li>Audit web server access logs for anomalous GET requests targeting the <code>/download/resources/</code> endpoint with traversal patterns containing <code>..%3a%3a</code> or <code>..::</code>.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>vulnerability</category><category>web-application</category><category>path-traversal</category></item></channel></rss>