Atlassian Security Updates 20 February 2023

Atlassian has released security updates to address vulnerabilities in the “Git” utility that affects multiple products.

The addressed vulnerabilities could allow the remote attacker to gain access to the affected systems.

Sample of the addressed vulnerabilities:

Git Integer Overflow Vulnerability (CVE-2022-41903):

• CVSS: 9.8

• Attack Vector: Network

• Attack Complexity: Low

• Privileges Required: None

• User Interaction: None

• Consequences: Gain Access

Sample of the affected products:

• Bitbucket Server and Data Center.

• Bamboo Server and Data Center.

• Fisheye.

• Crucible.

• Sourcetree.

It should be highlighted that the mentioned vulnerabilities are not limited to Atlassian products. It is recommended to check organizations’ systems and update Git utility to the latest version (2.38.3, 2.37.5, 2.36.4, 2.35.6, 2.34.6, 2.33.6, 2.32.5,2.31.6, 2.30.7, 2.39.1, or later).

Vulnerabilities
  • CVE-2022-41903
  • CVE-2022-23521
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Atlassian Security Advisory

References