CVE-2023-22521
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2023-22521 is a high severity Remote Code Execution (RCE) vulnerability affecting Atlassian's Crowd Data Center and Server, starting from version 3.4.6. With a CVSS score of 8.0, this issue allows authenticated attackers to execute arbitrary code, resulting in significant impacts on confidentiality, integrity, and availability. No user interaction is required to exploit this vulnerability. Atlassian urges Crowd Data Center and Server users to upgrade to the latest version to mitigate the risk. Users unable to upgrade immediately can consider upgrading to supported fixed versions: Crowd Data Center and Server 3.4 to 5.1.6 or Crowd Data Center and Server 5.2 to 5.2.1. The latest version can be downloaded from Atlassian's download center. This vulnerability was discovered by m1sn0w and reported through Atlassian's Bug Bounty program.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Atlassian Crowd
Affected Vendors
- Atlassian Corporation Pty Ltd.