CERT-In Vulnerability Note
CIVN-2023-0318
Multiple Vulnerabilities in Atlassian Products
Original Issue Date:October 21, 2023
Severity Rating: CRITICAL
Software Affected
- Confluence Server and Data Center
- Jira Service Management Data Center and Server
- Bitbucket Data Center and Server
- Bamboo Data Center and Server
- Sourcetree for Windows & Mac
Overview
Multiple vulnerabilities have been reported in Atlassian Products which could allow an attacker to bypass security restrictions, gain elevated privileges, obtain sensitive information, execute arbitrary code or can perform Denial of Service attacks on the targeted system.
Description
Multiple vulnerabilities have been reported in Atlassian Products; details of which are provided below:
Solution
Apply appropriate updates as mentioned:
https://confluence.atlassian.com/security/security-bulletin-october-17-2023-1299929380.html
Vendor Information
Atlassian
https://confluence.atlassian.com/security/security-bulletin-october-17-2023-1299929380.html
References
Atlassian
https://confluence.atlassian.com/security/security-bulletin-october-17-2023-1299929380.html
CVE Name
CVE-2023-22515
CVE-2019-13990
CVE-2022-3509
CVE-2022-3171
CVE-2021-22569
CVE-2022-42004
CVE-2022-42003
CVE-2021-46877
CVE-2020-36518
CVE-2021-31684
CVE-2023-1370
CVE-2023-25194
CVE-2022-25647
CVE-2022-45685
CVE-2022-45688
CVE-2022-40152
CVE-2023-28709
CVE-2023-22514
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|