Action Required: RCE Vulnerabilities Identified in Multiple Products

We have discovered four critical vulnerabilities impacting customers of the products listed below. All four vulnerabilities carry a critical CVSS score of 9.0 or higher, and customers must take immediate action to protect their instances.

Please carefully review all of the Critical Security Advisories impacting your Atlassian product(s) to verify affected versions and instructions.

CVE-2023-22524 - RCE Vulnerability in Atlassian Companion app for MacOS

  • Confluence Data Center and Server (former and present customers)

CVE-2023-22523 - RCE Vulnerability in Assets Discovery app

  • Jira Service Management Cloud

  • Jira Service Management Data Center and Server

CVE-2023-22522 - RCE Vulnerability in Confluence Data Center and Server

  • Confluence Data Center and Server

CVE-2022-1471 - SnakeYAML library RCE Vulnerability impacts Multiple Products

  • Bitbucket Data Center and Server

  • Confluence Data Center and Server

  • Confluence Cloud Migration Assistant (CCMA) app

  • Jira Core Data Center and Server

  • Jira Service Management Data Center and Server

  • Jira Software Data Center and Server

  • Automation for Jira (A4J) app (including Server Lite edition)

We found these vulnerabilities as part of an ongoing security review that we are conducting in addition to our continuous security assessments. Your security is our top priority, and we believe that acting proactively is the best approach to protecting your data.

Please follow the linked Critical Security Advisories for future updates.

10 comments

Alberto Yufra December 5, 2023

Links are broken!!

Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
December 5, 2023

@Alberto Yufra The links are working now.

Like # people like this
Dave Liao
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
December 5, 2023

Thanks for fixing the links!

David Yu
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
December 5, 2023

So how exploitable is the SnakeYAML issues on a private instance? It's not like we're letting strangers parse/upload YAML.

Stephen Hodgson December 6, 2023

How did Atlassian allow CVE-2022-1471 to remain in these products for a full year after that CVE was released?

This should have been picked up by any respectable package scanner a long time ago.

Like # people like this
Bryan Guffey
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
December 6, 2023

@Andy Heinzer - for clarification, on CVE-2022-1471, it looks as though Jira Software versions <9.0 are not impacted except through the Automation for Jira (A4J) or Automation for JIra (A4J) - Server Lite Marketplace apps, so if one is running Jira Software <9.0, one only needs to update the relevant Marketplace app, is that correct? 

Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
December 6, 2023

@Bryan Guffey Yes that is correct.

Vickey Palzor Lepcha
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
December 6, 2023

@Bryan Guffey   @Andy Heinzer   Looking at the Affected Version List - seems like versions less than 9.4 of JIRA Software is not impacted and not less than 9.0 ?

 

Leo Leung December 8, 2023

My Server products maintenance has been renewed every year since 2009 but it expired in Oct 2022 as I can see that support for Server products will end on Feb. 15, 2024.

Is there any way to provide security updates for security vulnerabilities that existed for years prior which affects all versions but only found and fixed in the latest release in 2023 without having to pay up to USD$3000 for each product to access the latest updates?

Some of these security flaws existed for the whole time I paid maintenance for the last 13 years!

Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
December 11, 2023

@Leo Leung While some of the CVEs have mitigations you can apply without an update, in order to resolve the vulnerability properly we typically have to create an updated version. We do not have a means grant these security fixes to expired licenses.  In order to apply these updated versions, you need to have a current and valid license applied to that product.  Our Software License Agreement explains that access to these updates is only provided to you during he period for which you paid:

6.1. Support and Maintenance. During the period for which you have paid the applicable Support and Maintenance fee, Atlassian will provide Support and Maintenance for the Software in accordance with the Atlassian Support Policy and Enterprise Support and Services Policy (if applicable).  Support and Maintenance for Software includes access to New Releases, if and when available, and any references to “Software” in this Agreement include New Releases.

You could renew your existing server license, but if I recall correctly, when renewing an expired license you still have to cover the period in between the expiration date and now, and furthermore, in regards to server license renewals, these can only be renewed until February 2024.

Alternatively, you could try to generate a Data Center evaluation on our https://my.atlassian.com however please be aware that when an eval or Data Center license expires, the product will stop working (this is different than your commercial server license, when that expires you can still use the product, but you are unable to obtain/apply updated versions released after that license expiration).  Also applying data center licenses to an existing server install could at least let you perform the upgrade, it might complicate the licensing of plugins/apps that might have different terms between server and data center editions.

Comment

Log in or Sign up to comment
TAGS
AUG Leaders

Atlassian Community Events