iTnews Asia
  • Home
  • News
  • Security

Atlassian issues urgent Confluence patch

Atlassian issues urgent Confluence patch

Template injection RCE fixed.

By Richard Chirgwin on Jan 17, 2024 11:04AM

Atlassian is warning users of out-of-date Confluence data centre and server environments that they need to update to a current version to patch a critical-rated vulnerability.

CVE-2023-22527 carries a CVSS score of 10 and is a template injection vulnerability that gives an unauthenticated attacker remote code execution (RCE) capability.

Recent supported versions are not affected, because the vulnerability was “ultimately mitigated during regular updates.”

Affected versions were released before December 5, 2023, and include 8.0.x, 8.1.x, 8.2.x, 8.3.x, 8.4.x, and 8.5.0-8.5.3.

The bug is fixed in Confluence data centre and server version 8.5.5 (LTS); and in Confluence data centre 8.7.2.

The company yesterday also released a security bulletin covering 28 high-rated vulnerabilities.

The fixes patch 14 denial-of-service bugs in the data centre and server versions of Bitbucket and Bamboo; information disclosure vulnerabilities in Crowd and Bamboo; six RCEs in Bamboo and Confluence; request smuggling vulnerabilities in Apache components used in Bitbucket, Bamboo, Crowd and Jira software; a server-side request forgery vulnerability in Jira service management; and an XML external entity injection bug in Jira software.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
atlassian confluence rce security

Related Articles

  • Proofpoint CEO: A tool-based approach for cybersecurity is impractical
  • Akamai: AI-security is both a security imperative and an economic necessity
  • The real-life Tom & Jerry chase
  • How can we bolster our resilience against AI-enabled e-mail attacks?
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Proofpoint CEO: A tool-based approach for cybersecurity is impractical

Proofpoint CEO: A tool-based approach for cybersecurity is impractical

The real-life Tom & Jerry chase

The real-life Tom & Jerry chase

How can we bolster our resilience against AI-enabled e-mail attacks?

How can we bolster our resilience against AI-enabled e-mail attacks?

Akamai: AI-security is both a security imperative and an economic necessity

Akamai: AI-security is both a security imperative and an economic necessity

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.