1:04pm, 7 December 2023
TLP Rating:
Four RCE vulnerabilities affecting Atlassian products
What's happening
Systems affected
- Confluence Data Center and Server
- Confluence Data Center (Data Center Only)
- Asset Discovery app for Jira Service Management products
- Atlassian Companion App for MacOS for Confluence Server and Confluence Data Center
- Automation for Jira app (including Server Lite edition)
- Bitbucket Data Center and Server
- Confluence Data Center and Server
- Confluence Cloud Migration App
- Jira Core Data Center and Server
- Jira Service Management Data Center and Server
- Jira Software Data Center and Server
What to do
Mitigation
Update the impacted Atlassian products as outlined below.
- 7.19.17 (LTS),
- 8.4.5, or
- 8.5.4 (LTS)
- version 8.6.2 or later (Data Center Only)
- 8.7.1 or later (Data Center Only)
- Asset Discovery 3.2.0-cloud or later
- Asset Discovery 6.2.0 or later
Confirm that Atlassian Companion App for MacOS has automatically updated to version 2.0.0 or later. If this is not compatible with your Confluence Data Center and Server instance you can uninstall the Atlassian Companion App to mitigate the vulnerability.
- Update the impacted Atlassian product to the version listed in the vendor advisory.
More information
- Atlassian website: RCE Vulnerability in Assets Discovery External Link
- Atlassian website: RCE Vulnerability in Atlassian Companion App for MacOS External Link
- Atlassian website: SnakeYAML library RCE Vulnerability impacts Multiple Products External Link
How helpful was this page?
This site is protected by reCAPTCHA and the Google Privacy Policy External Link and Terms of Service External Link apply.