Atlassian is being actively exploited to compromise corporate networks

Zero-day attack
(Image credit: Shutterstock) (Image credit: Shutterstock.com)

Two widely-used Atlassian Bitbucket tools - Server and Data Center, carry a high severity flaw that allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code, experts have warned. 

The flaw is being actively used in the wild, the US Cybersecurity and Infrastructure Agency (CISA) has noted, urging companies that use the tools to patch their endpoints immediately. Internet traffic analysts GreyNoise confirmed CISA’s findings, saying it had found evidence of the flaw being exploited.

The flaw is tracked as CVE-2022-36804, and was present in version 7.0.0 of both tools all the way up to version 8.3.0. Companies that are unable to apply the patch immediately should turn off public repositories to minimize the risk, Atlassian said.

Summer patching

The company confirmed the flaw’s existence in late August 2022, but this is not the first time this year that Atlassian had to patch major software flaws. 

Last summer, several of its popular products, including Jira, Confluence, and Bamboo were found to be carrying two high-severity vulnerabilities that allowed for remote code execution and privilege escalation.

The first vulnerability is tracked as CVE-2022-26136, an arbitrary Servlet Filter bypass, allowing threat actors to bypass custom Servlet Filters that third-party apps use for authentication. All they’d need to do is send a custom, malicious HTTP request.

The second vulnerability is tracked as CVE-2022-26137, and is described as a cross-origin resource sharing (CORS) bypass.

"Sending a specially crafted HTTP request can invoke the Servlet Filter used to respond to CORS requests, resulting in a CORS bypass,” Atlassian said. “An attacker that can trick a user into requesting a malicious URL can access the vulnerable application with the victim's permissions."

While these two flaws were found in a handful of Atlassian products, there was one more, found only in Confluence. The CVE-2022-26138 flaw is, in fact, a hard-coded password, set up to help cloud migrations. 

The flaws have since been patched.

Via: The Register

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
CISA tells agencies to patch BeyondTrust bug now
Avast cybersecurity
Hackers are hijacking government software to access sensitive servers
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
A person's fingers type at a keyboard, with a digital security screen with a lock on it overlaid.
Veeam backup software has a serious security flaw - here's how to stay safe
Cyber-security
Adobe releases software updates to patch security issues
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)