• News/
  • https://www.theregister.com/2024/01/16/patch_vmware_atlassian/

Patch now: Critical VMware, Atlassian flaws found

The Register
·
Jessica Lyons Hardcastle
·
Published Jan 16, 2024
·
Updated

VMware and Atlassian today disclosed critical vulnerabilities and, while neither appear to have been exploited by miscreants yet, admins should patch now to avoid disappointment. First off, a pair of issues from Atlassian. Most serious is CVE-2023-22527, a template injection flaw that can allow unauthenticated remote code execution (RCE) attacks. It scored a perfect CVSS rating of 10 out of 10 and affects Confluence Data Center and Server 8 versions released before December 5, 2023 and 8.4.5, which no longer receives fixes. The solution: "immediately" patch each affected installation by updating to the latest available version, according to the vendor. Atlassian also released fixes for a high-severity flaw was found in the FasterXML Jackson Databind code used in versions 8.20.0, 9.4.0, 9.5.0, and 9.6.0 of Jira Software Data Center and Server. The 7.5-rated bug, tracked as CVE-2020-25649, could allow XML external entity (XXE) attacks in which miscreants could mess with data integrity. So in addition to updating Confluence, it's also a good idea to upgrade to the latest version of Jira Software Data Center and Server, the collaboration biz advises. Moving on to the critical VMware bug, CVE-2023-34063. This one is a missing access control problem in all versions of Aria Automation earlier of 8.16. Be aware that this infrastructure automation product may be included in VMware Cloud Foundation. The bug earned a 9.9 CVSS rating, and VMware warns that successful exploitation can all...

Read full article

Affected Software

7 affected components
Atlassian Confluence Data Center=8
Atlassian Confluence Server=8
Atlassian Jira Software Data Center=8.20.0
Atlassian Jira Software Data Center=9.4.0
Atlassian Jira Software Data Center=9.5.0
Atlassian Jira Software Data Center=9.6.0
VMware Aria automation=8.16
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the discovery of critical vulnerabilities in VMware and Atlassian products that require immediate patching.

2

What security implications are discussed in the article?

The vulnerabilities pose significant security risks, although there are currently no indications of exploitation by attackers.

3

What products or software are affected by the vulnerabilities?

The affected products include Atlassian Confluence Server and Data Center, Jira Software Data Center versions, and VMware Aria Automation.

4

Which specific vulnerabilities are mentioned in relation to Atlassian products?

The article highlights a serious vulnerability categorized as CVE-2023-22 among other issues in Atlassian software.

5

What actions should administrators take in light of these vulnerabilities?

Administrators are advised to apply patches immediately to mitigate potential security risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203