News: 1705428588

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Patch now: Critical VMware, Atlassian flaws found

(2024/01/16)


VMware and Atlassian today disclosed critical vulnerabilities and, while neither appear to have been exploited by miscreants yet, admins should patch now to avoid disappointment.

First off, a pair of issues from Atlassian. Most serious is [1]CVE-2023-22527 , a template injection flaw that can allow unauthenticated remote code execution (RCE) attacks. It scored a perfect CVSS rating of 10 out of 10 and affects Confluence Data Center and Server 8 versions released before December 5, 2023 and 8.4.5, which no longer receives fixes.

The solution: "immediately" patch each affected installation by updating to the latest available version, according to the vendor.

[2]

Atlassian also released fixes for a high-severity flaw was found in the FasterXML Jackson Databind code used in versions 8.20.0, 9.4.0, 9.5.0, and 9.6.0 of Jira Software Data Center and Server. The 7.5-rated bug, tracked as [3]CVE-2020-25649 , could allow XML external entity (XXE) attacks in which miscreants could mess with data integrity.

[4]

[5]

So in addition to updating Confluence, it's also a good idea to upgrade to the latest version of Jira Software Data Center and Server, the collaboration biz advises.

[6]Atlassian security advisory reveals four fresh critical flaws – in mail with dead links

[7]Atlassian cranks up the threat meter to max for Confluence authorization flaw

[8]More than 178,000 SonicWall firewalls are exposed to old denial of service bugs

[9]Thousands of Juniper Networks devices vulnerable to critical RCE bug

Moving on to the critical VMware bug, [10]CVE-2023-34063 . This one is a missing access control problem in all versions of Aria Automation earlier of 8.16. Be aware that this infrastructure automation product may be included in VMware Cloud Foundation.

The bug earned a 9.9 CVSS rating, and VMware warns that successful exploitation can allow unauthorized access to remote organizations and workflows. Luckily this one also has a fix, so upgrade to VMware Aria Automation 8.16, and then apply the patch.

As the virtualization giant [11]notes : "The only supported upgrade path after applying the patch is to version 8.16. VMware strongly recommends this version. If you upgrade to an intermediate version, the vulnerability will be reintroduced, requiring an additional round of patching."

[12]

VMware isn't aware of any reports of exploitation "as of now." But it's safe to assume that would-be attackers are already scanning for vulnerable installations, so make sure to apply the fix before the software vendor is forced to update its advisory. ®

Get our [13]Tech Resources



[1] https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZacKlsPRXf4mTLB9h6t-1gAAAJQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.atlassian.com/trust/data-protection/vulnerabilities

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZacKlsPRXf4mTLB9h6t-1gAAAJQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZacKlsPRXf4mTLB9h6t-1gAAAJQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2023/12/06/atlassian_four_rce_cves/

[7] https://www.theregister.com/2023/11/08/atlassian_confluence_flaw_upgraded/

[8] https://www.theregister.com/2024/01/16/more_than_178000_sonicwall_firewalls/

[9] https://www.theregister.com/2024/01/15/juniper_networks_rce_flaw/

[10] https://www.vmware.com/security/advisories/VMSA-2024-0001.html

[11] https://core.vmware.com/resource/vmsa-2024-0001-questions-answers#are-there-more-details-on-the-vectors-of-the-individual-vul%20nerabilities

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZacKlsPRXf4mTLB9h6t-1gAAAJQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://whitepapers.theregister.com/



What does Confluence Data Center even do ?

t245t

“ [1]Confluence Data Center is a self-managed solution that provides you with the additional configuration options you need to meet the collaboration needs of the most demanding teams. This page provides an overview of options and considerations for large enterprises using Confluence.”

[1] https://confluence.atlassian.com/enterprise/confluence-data-center-resources-612959393.html

Re: What does Confluence Data Center even do ?

Claptrap314

With this bug, I would say, "Whatever an attacker wants"...

Re: What does Confluence Data Center even do ?

Anonymous Coward

Confluence is a glorified wiki.

Confluence Datacenter is the eye-wateringly priced replacement for the server version, for anyone daring/daft enough to want to host the thing themselves, rather than handing their IPR over to Atlassian.

Re: What does Confluence Data Center even do ?

Anonymous Coward

"Con-fluence".

As in "who conned management into buying this bloody thing?"

Freedom's just another word for nothing left to lose.
-- Kris Kristofferson, "Me and Bobby McGee"