First published: Wed Dec 06 2023(Updated: )
Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Atlassian Companion | >=1.0.0<2.0.0 | |
Apple iOS and macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22524 has been classified as a critical vulnerability due to its potential for remote code execution.
To mitigate CVE-2023-22524, users should update the Atlassian Companion App to the latest version available.
CVE-2023-22524 affects Atlassian Companion App versions between 1.0.0 and 2.0.0.
Yes, an attacker can exploit CVE-2023-22524 remotely by utilizing WebSockets to bypass security measures.
No, CVE-2023-22524 specifically affects the Atlassian Companion App on macOS.