
Atlassian has fixed four critical vulnerabilities in its software that could result in remote code execution.
The first vulnerability is CVE-2022-1471 with a CVSS score 9.8, is a Deserialization vulnerability in the SnakeYAML library that can lead to remote code execution in multiple products
The second vulnerability is CVE-2023-22522 with a CVSS score: 9.0 is a remote code execution vulnerability in Confluence Data Center and Confluence Server (affects all versions including and after 4.0.0)
The thrid vululnerability is CVE-2023-22523 with a CVSS score: 9.8 and it is also a remote code execution vulnerability in Assets Discovery for Jira Service Management Cloud, Server, and Data Center (affects all versions up to but not including 3.2.0-cloud / 6.2.0 data center and server)
The fourth and final vulnerability is CVE-2023-22524 with a CVSS score: 9.6 is a remote code execution vulnerability in the Atlassian Companion app for macOS (affects all versions up to but not including 2.0.0)
Atlassian says that CVE-2023-22522 as a template injection flaw that allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page, resulting in code execution.
The Assets Discovery flaw allows an attacker to perform privileged remote code execution on machines with the Assets Discovery agent installed, whereas CVE-2023-22524 could permit an attacker to achieve code execution by utilizing WebSockets to bypass Atlassian Companion’s blocklist and macOS Gatekeeper protections.
To remain safe, Atlassian recommends that customers update their applicable products to the latest version.