Too Long; Didn't Read
Check Point Research (CPR) uncovered chained vulnerabilities that together can be used to take over an account and control some of Atlassian apps connected through SSO. There were many affected domains. The first security issue was found on the subdomain training.atlassian.com. The Training platform offers users courses or credits. Check Point disclosed this information to the Atlassian teams and a solution was deployed to ensure its users can safely continue to share info on the various platforms. The vulnerability was discovered on November 16, 2020.