CVE-2023-22524: Critical severity Atlassian Companion vulnerability
Published Dec 6, 2023
·Updated
Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code.
Affected Software
2 affected components
All of the following
Atlassian Companion>=1.0.0<2.0.0
macOS
Event History
Dec 6, 2023
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
DescriptionSeverityWeakness
News Published
03:49 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-22524?
CVE-2023-22524 has been classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2023-22524?
To mitigate CVE-2023-22524, users should update the Atlassian Companion App to the latest version available.
3
Which versions of the Atlassian Companion App are affected by CVE-2023-22524?
CVE-2023-22524 affects Atlassian Companion App versions between 1.0.0 and 2.0.0.
4
Can an attacker exploit CVE-2023-22524 without physical access to the device?
Yes, an attacker can exploit CVE-2023-22524 remotely by utilizing WebSockets to bypass security measures.
5
Does CVE-2023-22524 impact other platforms besides macOS?
No, CVE-2023-22524 specifically affects the Atlassian Companion App on macOS.