Atlassian warns of 4 new critical vulnerabilities affecting Jira, Confluence, Bitbucket

Atlassian Jira, Confluence, Bitbucket and macOS Companion app users are warned to update their software immediately due to four critical vulnerabilities allowing for remote code execution.
Atlassian, an Australian software company, has more than 260,000 customers in more than 190 countries, including two-thirds of Fortune 500 companies.
One of the most severe bugs, rated by Atlassian as a 9.8 using the CVSS scale, requires Jira customers to uninstall Assets Discovery agent software from all devices before installing a patch to the main Assets Discovery application.
Another vulnerability, also rated 9.8, dates back to 2022 and is now known to impact a dozen Atlassian products including multiple Jira, Confluence and Bitbucket offerings.
Critical Atlassian vulnerabilities pose malware risks.
Security flaws affecting Jira, Confluence, Bitbucket and the Atlassian Companion app for macOS could be used by attackers to remotely execute malicious code.
Atlassian has released patches for all of these vulnerabilities, emphasizing the software updates are the only effective fix.
Ransomware exploitation of a previous Confluence bug, tracked as CVE-2023-22518, was reported last month.
One of the newly reported vulnerabilities, tracked as CVE-2023-22522, enables authenticated users to add code to a Confluence template, which is executed upon loading a Confluence page with that template.
Atlassian said users with anonymous access can also edit templates, which could help attackers evade detection.
The other three vulnerabilities could be exploited by unauthenticated attackers, the spokesperson said.
Another vulnerability impacts Jira customers that use the Assets Discovery application.
Atlassian said an RCE vulnerability, tracked as CVE-2023-22523, exists between Assets Discovery and Assets Discovery agents - software that allows offline devices to be detected by the Assets Discovery app.
All devices with an Asset Discovery agent installed need to have it manually uninstalled prior to the Asset Discovery app being updated for the vulnerability to be effectively patched, according to Atlassian.
Atlassian recommends blocking the port used to communicate with the agents as a temporary mitigation if all agents can not be immediately uninstalled.
Users of the Atlassian Companion app for Mac computers are also warned to update due to a flaw in which the WebSockets protocol can be used to bypass MacOS Gatekeeper and Atlassian Companion's blocklist to execute code on Confluence pages.
The Atlassian advisory also discloses that an RCE vulnerability discovered in December 2022 impacts 12 products across the Jira, Confluence and Bitbucket brands.
Atlassian said updating the SnakeYAML library is not sufficient, and the affected products must be updated to their latest versions to remediate the issue.
A full list of affected products is provided in Atlassian's advisory.
In addition to the discovery and exploitation of CVE-2023-22518 in November, Atlassian patched two other high-severity vulnerabilities affecting Jira, Confluence, Bitbucket and Bamboo in September.


This Cyber News was published on packetstormsecurity.com. Publication date: Tue, 12 Dec 2023 14:43:20 +0000


Cyber News related to Atlassian warns of 4 new critical vulnerabilities affecting Jira, Confluence, Bitbucket

Atlassian warns of 4 new critical vulnerabilities affecting Jira, Confluence, Bitbucket - Atlassian Jira, Confluence, Bitbucket and macOS Companion app users are warned to update their software immediately due to four critical vulnerabilities allowing for remote code execution. Atlassian, an Australian software company, has more than ...
1 year ago Packetstormsecurity.com
Atlassian warns of exploit for Confluence data wiping bug, get patching - Atlassian warned admins that a public exploit is now available for a critical Confluence security flaw that can be used in data destruction attacks targeting Internet-exposed and unpatched instances. Tracked as CVE-2023-22518, this is an improper ...
1 year ago Bleepingcomputer.com
Critical Atlassian Confluence bug exploited in Cerber ransomware attacks - Attackers are exploiting a recently patched and critical severity Atlassian Confluence authentication bypass flaw to encrypt victims' files using Cerber ransomware. Described by Atlassian as an improper authorization vulnerability and tracked as ...
1 year ago Bleepingcomputer.com
Fixing a Major Security Issue in Jira Service Management Server and Data Center - This week, a major security vulnerability was fixed in Jira Service Management Server, a popular IT services management platform for enterprises. This vulnerability could have allowed attackers to impersonate users and gain access to access tokens. ...
1 year ago Csoonline.com
Atlassian warns of critical RCE flaw in older Confluence versions - Atlassian Confluence Data Center and Confluence Server are vulnerable to a critical remote code execution vulnerability that impacts versions released before December 5, 2023, including out-of-support releases. The flaw is tracked as CVE-2023-22527, ...
11 months ago Bleepingcomputer.com
Atlassian Warns of Critical RCE Vulnerability in Outdated Confluence Instances - Enterprise software maker Atlassian on Tuesday warned of a critical vulnerability in out-of-date Confluence Data Center and Server versions that could be exploited for remote code execution, without authentication. The issue, tracked as ...
11 months ago Securityweek.com
CVE-2023-22513 - This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute ...
1 year ago
Atlassian Patches Critical Remote Code Execution Vulnerabilities - Business software maker Atlassian this week announced updates that address critical-severity remote code execution vulnerabilities in Confluence and other products. Atlassian, which rates the vulnerability with a CVSS score of 9.0, notes that an ...
1 year ago Securityweek.com
Alert: 'Effluence' Backdoor Persists Despite Patching Atlassian Confluence Servers - Cybersecurity researchers have discovered a stealthy backdoor named Effluence that's deployed following the successful exploitation of a recently disclosed security flaw in Atlassian Confluence Data Center and Server. "The malware acts as a ...
1 year ago Thehackernews.com
Atlassian patches critical RCE flaws across multiple products - Atlassian has published security advisories for four critical remote code execution vulnerabilities impacting Confluence, Jira, and Bitbucket servers, along with a companion app for macOS. All security issues addressed received a critical-severity ...
1 year ago Bleepingcomputer.com
Patch Now: Critical Atlassian Bugs Endanger Enterprise Apps - It's time to patch again: Four critical security vulnerabilities in Atlassian software open the door to remote code execution and subsequent lateral movement within enterprise environments. They are just the latest bugs to surface of late in the ...
1 year ago Darkreading.com
CVE-2024-21703 - This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and Server for Windows installations. This Security Misconfiguration vulnerability, with a CVSS Score of 6.4 allows an ...
3 weeks ago Tenable.com
Attacks begin on critical Atlassian Confluence vulnerability - Multiple cybersecurity organizations have observed exploitation attempts against a critical Atlassian Confluence vulnerability that was disclosed and patched last week. In a security advisory published on Jan. 16, Atlassian detailed a remote code ...
10 months ago Techtarget.com
Atlassian Confluence Server RCE attacks underway The Register - More than 600 IP addresses are launching thousands of exploit attempts against CVE-2023-22527 - a critical bug in out-of-date versions of Atlassian Confluence Data Center and Server - according to non-profit security org Shadowserver. Atlassian ...
10 months ago Go.theregister.com
CVE-2019-15006 - There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center. This plugin was used to facilitate communication with the Atlassian Companion application. The Confluence ...
3 years ago
CVE-2023-22505 - This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22505 was introduced in version 8.0.0 of Confluence Data Center & Server. ...
1 year ago
Patch ASAP: Max-Critical Atlassian Bug Allows Unauthenticated RCE - A max-critical unauthenticated remote code execution vulnerability is impacting Atlassian Confluence Data Center and Confluence Server, in all versions released before Dec. 5. Unpatched organizations should prepare to defend against everything from ...
11 months ago Darkreading.com
CVE-2024-21672 - This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. ...
10 months ago
CVE-2024-21673 - This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. ...
10 months ago
CVE-2024-21674 - This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. ...
10 months ago
CVE-2023-22526 - This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center. ...
10 months ago
CVE-2023-22508 - This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced in version 6.1.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an ...
1 year ago
CVE-2024-21677 - This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center. This Path Traversal vulnerability, with a CVSS Score of 8.3, allows an unauthenticated attacker to exploit an undefinable vulnerability which ...
9 months ago
CVE-2022-26136 - A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This ...
2 months ago
CVE-2022-26137 - A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security ...
2 months ago

Latest Cyber News


Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)