Article Details

Scrape Timestamp (UTC): 2023-12-06 11:11:58.035

Source: https://thehackernews.com/2023/12/atlassian-releases-critical-software.html

Original Article Text

Click to Toggle View

Atlassian Releases Critical Software Fixes to Prevent Remote Code Execution. Atlassian has released software fixes to address four critical flaws in its software that, if successfully exploited, could result in remote code execution. The list of vulnerabilities is below - Atlassian described CVE-2023-22522 as a template injection flaw that allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page, resulting in code execution. The Assets Discovery flaw allows an attacker to perform privileged remote code execution on machines with the Assets Discovery agent installed, whereas CVE-2023-22524 could permit an attacker to achieve code execution by utilizing WebSockets to bypass Atlassian Companion's blocklist and macOS Gatekeeper protections. The advisory comes nearly a month after the Australian software company revealed all versions of its Bamboo Data Center and Server products are impacted by an actively exploited critical security flaw in Apache ActiveMQ (CVE-2023-46604, CVSS score: 10.0). Fixes have been released in versions 9.2.7, 9.3.5, and 9.4.1 or later. With Atlassian products becoming lucrative attack vectors in recent years, it's highly recommended that users move quickly to update affected installations to a patched version.

Daily Brief Summary

MALWARE // Atlassian Patches Critical Vulnerabilities to Thwart Remote Attacks

Atlassian has issued important software updates to rectify four critical security flaws that could lead to remote code execution.

The identified vulnerabilities include a template injection issue (CVE-2023-22522) in Confluence that could allow code execution through user input.

Another flaw involves the Assets Discovery agent, enabling attackers to perform privileged remote code execution on connected machines.

CVE-2023-22524 presents a risk where attackers could use WebSockets to sidestep blocklists and protections in Atlassian Companion and macOS Gatekeeper.

Previously, Atlassian addressed a severe security weakness in Apache ActiveMQ (CVE-2023-46604) affecting Bamboo Data Center and Server products.

Versions released to correct these issues are 9.2.7, 9.3.5, and 9.4.1 or later, with urgent updates recommended due to increased attacks on Atlassian tools.