Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Atlassian heeft kwetsbaarheden verholpen in diverse producten, zoals Jira, Confluence en Bitbucket.
- Interpretaties
Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Cross-Site Request Forgery (XSRF)
- Denial-of-Service (DoS)
- Omzeilen van authenticatie
- (Remote) code execution (Administrator/Root rechten)
- (Remote) code execution (Gebruikersrechten)
- SQL Injection
- Toegang tot systeemgegevens
- Oplossingen
Atlassian heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie:
https://confluence.atlassian.com/security/security-bulletin-may-21-2024-1387867145.html
- Kans
medium
- Schade
high
- CWE-284
Improper Access Control
- CWE-20
Improper Input Validation
- CWE-281
Improper Preservation of Permissions
- CWE-400
Uncontrolled Resource Consumption
- CWE-404
Improper Resource Shutdown or Release
- CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
- CWE-459
Incomplete Cleanup
- CWE-502
Deserialization of Untrusted Data
- CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
- CWE-770
Allocation of Resources Without Limits or Throttling
- CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- CWE-913
Improper Control of Dynamically-Managed Code Resources
- CWE-96
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard