Atlassian reveals details of further security flaws, so patch now

Red padlock open on electric circuits network dark red background
(Image credit: Shutterstock/Chor muang)

Atlassian has discovered and patched four critical vulnerabilities, and is now urging its users to apply fixes immediately. 

All of the flaws have at least a 9.0 severity rating and allow threat actors to run remote code execution (RCE). The first flaw is CVE‑2022‑1471. It carries a 9.8 severity score and affects Automation for Jira app (including Server Lite edition), Bitbucket Data Center, Bitbucket Server, Confluence Data Center, Confluence Server, Confluence Cloud Migration App, Jira Core Data Center, Jira Core Server, Jira Service Management Data Center, Jira Service Management Server, Jira Software Data Center, and Jira Software Server.

The second flaw is CVE‑2023‑22522, with a severity score of 9.0 and affecting Confluence Data Center and Server.

Updating the software

The third flaw is CVE‑2023‑22524, coming in at 9.6 and affecting Atlassian Companion App for MacOS, Jira Service Management Cloud, Data Center and Server, while the fourth and final one is CVE‑2023‑22523 (9.8) affecting the Assets Discovery app for Assets Discovery for Jira Service Management Cloud, Jira Service Management Server and Jira Service Management Data Center.

The fix for all of the above is the same and requires upgrading the software to the latest versions. 

Atlassian has had plenty of severe flaws to fix in the past couple of weeks. Less than a month ago, the company released a patch for a high-severity flaw found in Confluence. In early November, it was reported that Atlassian fixed an improper authorization flaw found in all versions of Confluence Data Center and Confluence Server. It’s being tracked as CVE-2023-22518 and carries a severity score of 9.1. Hackers can use it to destroy data found on the affected servers. A few days later, Atlassian warned that the abuse of the flaw was “widespread”. In some cases, researchers found, hackers were using the flaw to drop ransomware on their victims’ endpoints.

Via The Register

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Representational image depecting cybersecurity protection
Ivanti reveals major security update, so make sure you're protected
Image depicting a hand on a scanner
Hackers are targeting unpatched ServiceNow instances that exploit 3 separate year-old vulnerabilities
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
A person's fingers type at a keyboard, with a digital security screen with a lock on it overlaid.
Veeam backup software has a serious security flaw - here's how to stay safe
Cyber-security
Adobe releases software updates to patch security issues
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)