Atlassian Security Updates – 24 July 2023

Atlassian has released security updates to address several vulnerabilities in Atlassian Confluence and Atlassian Bamboo.

The severity of the addressed vulnerabilities could allow the remote attacker to gain access, and execute arbitrary code on the affected systems.

Sample of the addressed vulnerabilities:

Atlassian Confluence Data Center and Atlassian Confluence Server Code Execution Vulnerability (CVE-2023-22508):

  • CVSS: 8.5
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Access

Affected Products:

  • Atlassian Confluence Data Center and Server >= (7.4.0, 8.0.0).
  • Atlassian Bamboo Data Center and Server >= 8.0.0.
Vulnerabilities
  • CVE-2023-22505
  • CVE-2023-22506
  • CVE-2023-22508
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Atlassian Security Updates

References