CVE-2023-22521

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Nov 21, 2023
Updated: Nov 29, 2023

Summary

CVE-2023-22521 is a high severity Remote Code Execution (RCE) vulnerability affecting Atlassian's Crowd Data Center and Server, starting from version 3.4.6. With a CVSS score of 8.0, this issue allows authenticated attackers to execute arbitrary code, resulting in significant impacts on confidentiality, integrity, and availability. No user interaction is required to exploit this vulnerability. Atlassian urges Crowd Data Center and Server users to upgrade to the latest version to mitigate the risk. Users unable to upgrade immediately can consider upgrading to supported fixed versions: Crowd Data Center and Server 3.4 to 5.1.6 or Crowd Data Center and Server 5.2 to 5.2.1. The latest version can be downloaded from Atlassian's download center. This vulnerability was discovered by m1sn0w and reported through Atlassian's Bug Bounty program.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Atlassian Crowd

Affected Vendors

  • Atlassian Corporation Pty Ltd.