Article Details

Scrape Timestamp (UTC): 2023-12-06 11:11:58.379

Source: https://www.theregister.com/2023/12/06/atlassian_four_rce_cves/

Original Article Text

Click to Toggle View

Atlassian security advisory reveals four fresh critical flaws – in mail with dead links. Bitbucket, Confluence and Jira all in danger, again. Sigh. Atlassian has emailed its customers to warn of four critical vulnerabilities, but the message had flaws of its own – the links it contained weren't live for all readers at the time of despatch. The email, seen by The Register, warns of flaws rated 9.0 or higher on the Common Vulnerability Scoring System (CVSS) scale and offers a link to an advisory. But that link was to a page that did not describe the relevant flaws, instead detailing CVE-2023-22518, the 9.1-rated stinker revealed in late October and later upgraded to a perfect 10/10. Nor did links to the four CVEs the email mentions reach the correct page for around an hour – all produced a Page Not Found error and a suggestion that the page may have been renamed with another URL that does carry the correct information. Atlassian told us "There was a small error where emails went out to some customers with broken links. As soon as we realized we put a workaround in place so customers were redirected to the appropriate pages. We apologize to our customers for any frustration caused with our mistake." The URLs all include URLdefense.com – a service offered by Proofpoint. Maybe it was Proofpoint's problem. While the links were dead, Atlassian did manage to publish info about the four fresh problems here. The four flaws all allow remote code execution and impact the products listed below: The fix for all the flaws is the same: upgrade the product to a fixed version. Atlassian's emailed advisory urges "you must take immediate action to protect your instance." The Register imagines that was a hard instruction to follow, given the dud links the email contained for some customers. Atlassian's stated company values include "Don't #@!% the customer" and "Open company, no bullshit."

Daily Brief Summary

CYBERCRIME // Atlassian Warns of Critical Vulnerabilities Amid Advisory Glitches

Atlassian issued an email advisory about four critical vulnerabilities across several products, including Bitbucket, Confluence, and Jira.

The email contained incorrect links, which initially led to a 'Page Not Found' error, delaying access to vital security information.

Affected links were later redirected to the correct pages following realization of the error by Atlassian.

The vulnerabilities are rated 9.0 or higher on the CVSS scale and allow remote code execution, posing a severe security risk.

Customers are advised to upgrade their Atlassian products to the latest fixed versions to mitigate the threat immediately.

Atlassian has publicly recognized the email error and issued an apology for any inconvenience caused to customers.