• Atlassian reveals details of further security flaws, so patch now

    From TechnologyDaily@1337:1/100 to All on Wed Dec 6 12:45:05 2023
    Atlassian reveals details of further security flaws, so patch now

    Date:
    Wed, 06 Dec 2023 12:43:45 +0000

    Description:
    Four high-severity flaws were recently discovered and Atlassian is urging users to patch their instances immediately.

    FULL STORY ======================================================================

    Atlassian has discovered and patched four critical vulnerabilities, and is
    now urging its users to apply fixes immediately.

    All of the flaws have at least a 9.0 severity rating and allow threat actors to run remote code execution (RCE). The first flaw is CVE20221471. It carries a 9.8 severity score and affects Automation for Jira app (including Server Lite edition), Bitbucket Data Center, Bitbucket Server, Confluence Data Center, Confluence Server, Confluence Cloud Migration App, Jira Core Data Center, Jira Core Server, Jira Service Management Data Center, Jira Service Management Server, Jira Software Data Center, and Jira Software Server.

    The second flaw is CVE202322522, with a severity score of 9.0 and affecting Confluence Data Center and Server. Updating the software

    The third flaw is CVE202322524, coming in at 9.6 and affecting Atlassian Companion App for MacOS, Jira Service Management Cloud, Data Center and Server, while the fourth and final one is CVE202322523 (9.8) affecting the Assets Discovery app for Assets Discovery for Jira Service Management Cloud, Jira Service Management Server and Jira Service Management Data Center.

    The fix for all of the above is the same and requires upgrading the software to the latest versions.

    Atlassian has had plenty of severe flaws to fix in the past couple of weeks. Less than a month ago, the company released a patch for a high-severity flaw found in Confluence. In early November, it was reported that Atlassian fixed an improper authorization flaw found in all versions of Confluence Data
    Center and Confluence Server. Its being tracked as CVE-2023-22518 and carries a severity score of 9.1. Hackers can use it to destroy data found on the affected servers. A few days later, Atlassian warned that the abuse of the flaw was widespread. In some cases, researchers found, hackers were using the flaw to drop ransomware on their victims endpoints .

    Via The Register More from TechRadar Pro A critical security flaw in Atlassian Confluence is now being majorly exploited Here's a list of the best firewalls today These are the best malware removal tools right now



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/atlassian-reveals-details-of-further-se curity-flaws-so-patch-now


    --- Mystic BBS v1.12 A47 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)