VMware and Atlassian today disclosed critical vulnerabilities and, while neither appear to have been exploited by miscreants yet, admins should patch now to avoid disappointment. First off, a pair of issues from Atlassian. Most serious is CVE-2023-22527, a template injection flaw that can allow unauthenticated remote code execution (RCE) attacks. It scored a perfect CVSS rating of 10 out of 10 and affects Confluence Data Center and Server 8 versions released before December 5, 2023 and 8.4.5, which no longer receives fixes. The solution: "immediately" patch each affected installation by updating to the latest available version, according to the vendor. Atlassian also released fixes for a high-severity flaw was found in the FasterXML Jackson Databind code used in versions 8.20.0, 9.4.0, 9.5.0, and 9.6.0 of Jira Software Data Center and Server. The 7.5-rated bug, tracked as CVE-2020-25649, could allow XML external entity (XXE) attacks in which miscreants could mess with data integrity. So in addition to updating Confluence, it's also a good idea to upgrade to the latest version of Jira Software Data Center and Server, the collaboration biz advises. Moving on to the critical VMware bug, CVE-2023-34063. This one is a missing access control problem in all versions of Aria Automation earlier of 8.16. Be aware that this infrastructure automation product may be included in VMware Cloud Foundation. The bug earned a 9.9 CVSS rating, and VMware warns that successful exploitation can all...
Patch now: Critical VMware, Atlassian flaws found
The Register
·Jessica Lyons Hardcastle
·Published Jan 16, 2024
·Updated
Affected Software
7 affected components
Atlassian Confluence Data Center=8
Atlassian Confluence Server=8
Atlassian Jira Software Data Center=8.20.0
Atlassian Jira Software Data Center=9.4.0
Atlassian Jira Software Data Center=9.5.0
Atlassian Jira Software Data Center=9.6.0
VMware Aria automation=8.16
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the discovery of critical vulnerabilities in VMware and Atlassian products that require immediate patching.
2
What security implications are discussed in the article?
The vulnerabilities pose significant security risks, although there are currently no indications of exploitation by attackers.
3
What products or software are affected by the vulnerabilities?
The affected products include Atlassian Confluence Server and Data Center, Jira Software Data Center versions, and VMware Aria Automation.
4
Which specific vulnerabilities are mentioned in relation to Atlassian products?
The article highlights a serious vulnerability categorized as CVE-2023-22 among other issues in Atlassian software.
5
What actions should administrators take in light of these vulnerabilities?
Administrators are advised to apply patches immediately to mitigate potential security risks.