Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2024-0231

Published May 22, 2024·Last modified May 22, 2024
Description
Feiten

Atlassian heeft kwetsbaarheden verholpen in diverse producten, zoals Jira, Confluence en Bitbucket.

Interpretaties

Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:

  • Cross-Site Request Forgery (XSRF)
  • Denial-of-Service (DoS)
  • Omzeilen van authenticatie
  • (Remote) code execution (Administrator/Root rechten)
  • (Remote) code execution (Gebruikersrechten)
  • SQL Injection
  • Toegang tot systeemgegevens
Oplossingen

Atlassian heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie:

https://confluence.atlassian.com/security/security-bulletin-may-21-2024-1387867145.html

Kans

medium

Schade

high

CWE-284

Improper Access Control

CWE-20

Improper Input Validation

CWE-281

Improper Preservation of Permissions

CWE-400

Uncontrolled Resource Consumption

CWE-404

Improper Resource Shutdown or Release

CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CWE-459

Incomplete Cleanup

CWE-502

Deserialization of Untrusted Data

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

CWE-770

Allocation of Resources Without Limits or Throttling

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CWE-913

Improper Control of Dynamically-Managed Code Resources

CWE-96

Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard