Improved Security: Atlassian Addresses Multiple Critical Vulnerabilities with Patches

Atlassian has released patches to address several critical vulnerabilities. The first vulnerability, CVE-2023-22522, is a template injection vulnerability in Confluence Data Centre and Confluence Server. This vulnerability allows an attacker to inject unsafe user input into a Confluence page, granting them remote code execution. It affects all versions of Confluence Data Centre and Server after version 4.0.0, and users are advised to upgrade to a fixed version.

Another vulnerability, CVE-2023-22524, is a remote code execution vulnerability in the Atlassian Companion App for MacOS. Attackers can use WebSockets to bypass the app’s blocklist and MacOS Gatekeeper, enabling the execution of code.

CVE-2023-22523 is a critical-rated bug in Asset Discovery in Jira Service Management Cloud, Server, and Data Centre. This vulnerability exists between the Assets Discovery application and the Assets Discovery agent, allowing attackers to gain privileged remote code execution.

Lastly, CVE-2022-1471 is a remote code execution deserialization bug in the SnakeYAML library, which is utilized in multiple Atlassian products such as Automation for Jira, BitBucket, Confluence, and Jira configurations. Patches are available for affected versions of these products.

Unlock your business potential with our expert guidance. Get in touch now!

Hero-Coding-Flashizzle-peopleimages-com-14.jpg

Gaining Insight into ‘Black Box’ IT Systems Can Mitigate Risks Similar to the Post Office Scandal

tra_20240927-desksense-ai-assistant-lifetime-subscription.jpg

Transform Your To-Do List into Achievements with DeskSense—Your Life AI Assistant

charts-graphs-data-BraveSpirit-adobe.jpg

Harnessing Data’s Potential: Revolutionizing Industrial Growth in the UK

ew_20240312-openai-api-ai-agent.webp.webp

OpenAI Agents Now Compatible with Competitor Anthropic’s Protocol

cloud-threat-adobe.jpg

Microsoft’s ‘Strained Partnership’ with OpenAI Cited as Reason for Scaling Back Data Center Expansion Plans

lenovo-tablet-amazon-mar-25.jpg

Amazon Prime Big Spring Sale: Top Tech Discounts

staff-recruitment-CV-Feodora-adobe.jpg

Whitehall’s AI Chief Calls for Overhaul of Government Tech Staff Hiring Process