News: 1701845827

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Atlassian security advisory reveals four fresh critical flaws – in mail with dead links

(2023/12/06)


Atlassian has emailed its customers to warn of four critical vulnerabilities, but the message had flaws of its own – the links it contained weren't live for all readers at the time of despatch.

The email, seen by The Register , warns of flaws rated 9.0 or higher on the Common Vulnerability Scoring System (CVSS) scale and offers a link to an advisory.

But that link was to a page that did not describe the relevant flaws, instead detailing [1]CVE-2023-22518 , the 9.1-rated stinker revealed in late October and later [2]upgraded to a perfect 10/10. Nor did links to the four CVEs the email mentions reach the correct page for around an hour – all produced a Page Not Found error and a suggestion that the page may have been renamed with another URL that does carry the correct information.

[3]

Atlassian told us "There was a small error where emails went out to some customers with broken links. As soon as we realized we put a workaround in place so customers were redirected to the appropriate pages. We apologize to our customers for any frustration caused with our mistake."

[4]

[5]

The URLs all include URLdefense.com – a service offered by Proofpoint. Maybe it was Proofpoint's problem.

While the links were dead, Atlassian did manage to publish info about the four fresh problems [6]here .

[7]

The four flaws all allow remote code execution and impact the products listed below:

CVE‑2022‑1471 – 9.8/10 – Automation for Jira app (including Server Lite edition), Bitbucket Data Center, Bitbucket Server, Confluence Data Center, Confluence Server, Confluence Cloud Migration App, Jira Core Data Center, Jira Core Server, Jira Service Management Data Center, Jira Service Management Server, Jira Software Data Center, Jira Software Server

CVE‑2023‑22522 – 9.0/10 – Confluence Data Center and Server

CVE‑2023‑22524 – 9.6/10 – Atlassian Companion App for MacOS, Jira Service Management Cloud, Data Center and Server

CVE‑2023‑22523 – 9.8/10 – Assets Discovery app for Assets Discovery for Jira Service Management Cloud, Jira Service Management Server and Jira Service Management Data Center

The fix for all the flaws is the same: upgrade the product to a fixed version.

[8]Atlassian cranks up the threat meter to max for Confluence authorization flaw

[9]US cybercops urge admins to patch amid ongoing Confluence chaos

[10]How does Atlassian hope to actually improve Confluence and Jira? AI, of course!

[11]Atlassian predicts its on-prem products will grow faster than cloud

Atlassian's emailed advisory urges "you must take immediate action to protect your instance." The Register imagines that was a hard instruction to follow, given the dud links the email contained for some customers.

Atlassian's stated [12]company values include "Don't #@!% the customer" and "Open company, no bullshit." ®

Get our [13]Tech Resources



[1] https://www.theregister.com/2023/10/31/critical_atlassian_confluence_flaw/

[2] https://www.theregister.com/2023/11/08/atlassian_confluence_flaw_upgraded/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZXBUWGlOlZaS4Dp6MQoHygAAAIQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXBUWGlOlZaS4Dp6MQoHygAAAIQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZXBUWGlOlZaS4Dp6MQoHygAAAIQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://confluence.atlassian.com/security/december-2023-security-advisories-overview-1318892103.html

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXBUWGlOlZaS4Dp6MQoHygAAAIQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2023/11/08/atlassian_confluence_flaw_upgraded/

[9] https://www.theregister.com/2023/10/17/confluence_zero_day_advisory/

[10] https://www.theregister.com/2023/04/19/atlassian_ai/

[11] https://www.theregister.com/2023/11/03/atlassian_q1_2024/

[12] https://www.atlassian.com/company/values

[13] https://whitepapers.theregister.com/



veti

In other news, Atlassian announces it will no longer use ChatGPT to spam its customers write its user notifications.

CowHorseFrog

How are Atlassian even alive at this point. Everything they touch turns to absolute shit. THey are supposedly a developer tool company to some extent, and yet basically everyone one of their products is a perfect example of how not to do things. So why would anyone continue to buy their crap ?

What if nothing exists and we're all in somebody's dream? Or what's worse,
what if only that fat guy in the third row exists?
-- Woody Allen, "Without Feathers"