Vulnerabilites related to atlassian - assets_discovery_data_center
Vulnerability from fkie_nvd
Published
2023-12-06 05:15
Modified
2024-11-21 07:44
Severity ?
Summary
This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets Discovery agent.
References
Impacted products
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:atlassian:assets_discovery_cloud:*:*:*:*:*:*:*:*", "matchCriteriaId": "B605B443-2604-4D2D-99C2-EF7D955B1886", "versionEndExcluding": "3.2.0", "versionStartIncluding": "1.0.0", "vulnerable": true }, { "criteria": "cpe:2.3:a:atlassian:assets_discovery_data_center:*:*:*:*:*:*:*:*", "matchCriteriaId": "6EE9C216-E2F8-4BDB-A67B-095AA0B19613", "versionEndIncluding": "3.1.11", "versionStartIncluding": "1.0.0", "vulnerable": true }, { "criteria": "cpe:2.3:a:atlassian:assets_discovery_data_center:*:*:*:*:*:*:*:*", "matchCriteriaId": "C95EF896-3AE4-400B-B4BD-61D909D91B5B", "versionEndExcluding": "6.2.0", "versionStartIncluding": "6.0.0", "vulnerable": true }, { "criteria": "cpe:2.3:a:atlassian:assets_discovery_data_server:*:*:*:*:*:*:*:*", "matchCriteriaId": "63079045-C71C-4D37-9B05-BD3705B90B37", "versionEndIncluding": "3.1.11", "versionStartIncluding": "1.0.0", "vulnerable": true }, { "criteria": "cpe:2.3:a:atlassian:assets_discovery_data_server:*:*:*:*:*:*:*:*", "matchCriteriaId": "329E8EB1-FEAC-4C29-B443-4AB31D5DBC95", "versionEndExcluding": "6.2.0", "versionStartIncluding": "6.0.0", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets Discovery agent." }, { "lang": "es", "value": "Esta vulnerabilidad, si se explota, permite a un atacante realizar RCE (ejecuci\u00f3n remota de c\u00f3digo) privilegiada en m\u00e1quinas con el agente Assets Discovery instalado. La vulnerabilidad existe entre la aplicaci\u00f3n Assets Discovery (anteriormente conocida como Insight Discovery) y el agente Assets Discovery." } ], "id": "CVE-2023-22523", "lastModified": "2024-11-21T07:44:58.633", "metrics": { "cvssMetricV30": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "exploitabilityScore": 3.9, "impactScore": 5.9, "source": "security@atlassian.com", "type": "Secondary" } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2023-12-06T05:15:10.087", "references": [ { "source": "security@atlassian.com", "tags": [ "Vendor Advisory" ], "url": "https://confluence.atlassian.com/security/cve-2023-22523-rce-vulnerability-in-assets-discovery-1319248914.html" }, { "source": "security@atlassian.com", "tags": [ "Issue Tracking", "Vendor Advisory" ], "url": "https://jira.atlassian.com/browse/JSDSERVER-14925" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://confluence.atlassian.com/security/cve-2023-22523-rce-vulnerability-in-assets-discovery-1319248914.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Issue Tracking", "Vendor Advisory" ], "url": "https://jira.atlassian.com/browse/JSDSERVER-14925" } ], "sourceIdentifier": "security@atlassian.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "NVD-CWE-noinfo" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-02-20 18:15
Modified
2025-04-30 14:06
Severity ?
Summary
This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions).
Assets Discovery, which can be downloaded via Atlassian Marketplace, is a network scanning tool that can be used with or without an agent with Jira Service Management Cloud, Data Center or Server. It detects hardware and software that is connected to your local network and extracts detailed information about each asset. This data can then be imported into Assets in Jira Service Management to help you manage all of the devices and configuration items within your local network.
This Injection vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to modify the actions taken by a system call which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.
Atlassian recommends that Assets Discovery customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions
See the release notes (https://confluence.atlassian.com/assetapps/assets-discovery-3-2-1-cloud-6-2-1-data_center-1333987182.html). You can download the latest version of Assets Discovery from the Atlassian Marketplace (https://marketplace.atlassian.com/apps/1214668/assets-discovery?hosting=datacenter&tab=installation).
This vulnerability was reported via our Penetration Testing program.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
atlassian | assets_discovery_data_center | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:atlassian:assets_discovery_data_center:*:*:*:*:*:*:*:*", "matchCriteriaId": "92207FBE-A735-4744-9841-308C48C855EC", "versionEndExcluding": "6.2.1", "versionStartIncluding": "1.0.0", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). \n\nAssets Discovery, which can be downloaded via Atlassian Marketplace, is a network scanning tool that can be used with or without an agent with Jira Service Management Cloud, Data Center or Server. It detects hardware and software that is connected to your local network and extracts detailed information about each asset. This data can then be imported into Assets in Jira Service Management to help you manage all of the devices and configuration items within your local network.\n\nThis Injection vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to modify the actions taken by a system call which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.\n\nAtlassian recommends that Assets Discovery customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions\n\nSee the release notes (https://confluence.atlassian.com/assetapps/assets-discovery-3-2-1-cloud-6-2-1-data_center-1333987182.html). You can download the latest version of Assets Discovery from the Atlassian Marketplace (https://marketplace.atlassian.com/apps/1214668/assets-discovery?hosting=datacenter\u0026tab=installation).\n\nThis vulnerability was reported via our Penetration Testing program." }, { "lang": "es", "value": "Esta vulnerabilidad de inyecci\u00f3n de alta gravedad se introdujo en Assets Discovery 1.0 - 6.2.0 (todas las versiones). Assets Discovery, que se puede descargar a trav\u00e9s de Atlassian Marketplace, es una herramienta de escaneo de red que se puede usar con o sin un agente con Jira Service Management Cloud, Data Center o Server. Detecta hardware y software que est\u00e1 conectado a su red local y extrae informaci\u00f3n detallada sobre cada activo. Luego, estos datos se pueden importar a Activos en Jira Service Management para ayudarlo a administrar todos los dispositivos y elementos de configuraci\u00f3n dentro de su red local. Esta vulnerabilidad de inyecci\u00f3n, con una puntuaci\u00f3n CVSS de 7,2, permite a un atacante autenticado modificar las acciones tomadas por una llamada al sistema, lo que tiene un alto impacto en la confidencialidad, un alto impacto en la integridad, un alto impacto en la disponibilidad y no requiere interacci\u00f3n del usuario. Atlassian recomienda que los clientes de Assets Discovery actualicen a la \u00faltima versi\u00f3n; si no puede hacerlo, actualice su instancia a una de las versiones fijas admitidas especificadas. Consulte las notas de la versi\u00f3n (https://confluence.atlassian.com/assetapps/assets-discovery -3-2-1-nube-6-2-1-data_center-1333987182.html). Puede descargar la \u00faltima versi\u00f3n de Assets Discovery desde Atlassian Marketplace (https://marketplace.atlassian.com/apps/1214668/assets-discovery?hosting=datacenter\u0026amp;tab=installation). Esta vulnerabilidad se inform\u00f3 a trav\u00e9s de nuestro programa de pruebas de penetraci\u00f3n." } ], "id": "CVE-2024-21682", "lastModified": "2025-04-30T14:06:22.117", "metrics": { "cvssMetricV30": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.2, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "HIGH", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "exploitabilityScore": 1.2, "impactScore": 5.9, "source": "security@atlassian.com", "type": "Secondary" } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.2, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "HIGH", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.2, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2024-02-20T18:15:51.063", "references": [ { "source": "security@atlassian.com", "tags": [ "Release Notes" ], "url": "https://confluence.atlassian.com/assetapps/assets-discovery-3-2-1-cloud-6-2-1-data_center-1333987182.html" }, { "source": "security@atlassian.com", "tags": [ "Vendor Advisory" ], "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1354501606" }, { "source": "security@atlassian.com", "tags": [ "Issue Tracking", "Vendor Advisory" ], "url": "https://jira.atlassian.com/browse/JSDSERVER-15067" }, { "source": "security@atlassian.com", "tags": [ "Product" ], "url": "https://marketplace.atlassian.com/apps/1214668/assets-discovery?hosting=datacenter\u0026tab=installation" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Release Notes" ], "url": "https://confluence.atlassian.com/assetapps/assets-discovery-3-2-1-cloud-6-2-1-data_center-1333987182.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1354501606" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Issue Tracking", "Vendor Advisory" ], "url": "https://jira.atlassian.com/browse/JSDSERVER-15067" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Product" ], "url": "https://marketplace.atlassian.com/apps/1214668/assets-discovery?hosting=datacenter\u0026tab=installation" } ], "sourceIdentifier": "security@atlassian.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-94" } ], "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }
CVE-2024-21682 (GCVE-0-2024-21682)
Vulnerability from cvelistv5
Published
2024-02-20 18:00
Modified
2024-08-28 15:56
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Injection
Summary
This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions).
Assets Discovery, which can be downloaded via Atlassian Marketplace, is a network scanning tool that can be used with or without an agent with Jira Service Management Cloud, Data Center or Server. It detects hardware and software that is connected to your local network and extracts detailed information about each asset. This data can then be imported into Assets in Jira Service Management to help you manage all of the devices and configuration items within your local network.
This Injection vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to modify the actions taken by a system call which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.
Atlassian recommends that Assets Discovery customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions
See the release notes (https://confluence.atlassian.com/assetapps/assets-discovery-3-2-1-cloud-6-2-1-data_center-1333987182.html). You can download the latest version of Assets Discovery from the Atlassian Marketplace (https://marketplace.atlassian.com/apps/1214668/assets-discovery?hosting=datacenter&tab=installation).
This vulnerability was reported via our Penetration Testing program.
References
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
Atlassian | Assets Discovery Data Center |
Version: >= 6.0.0 Version: >= 6.1.0 Version: >= 6.2.0 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-01T22:27:35.986Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://confluence.atlassian.com/assetapps/assets-discovery-3-2-1-cloud-6-2-1-data_center-1333987182.html" }, { "tags": [ "x_transferred" ], "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1354501606" }, { "tags": [ "x_transferred" ], "url": "https://jira.atlassian.com/browse/JSDSERVER-15067" }, { "tags": [ "x_transferred" ], "url": "https://marketplace.atlassian.com/apps/1214668/assets-discovery?hosting=datacenter\u0026tab=installation" } ], "title": "CVE Program Container" }, { "affected": [ { "cpes": [ "cpe:2.3:a:atlassian:assets_discovery_data_center:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "assets_discovery_data_center", "vendor": "atlassian", "versions": [ { "lessThanOrEqual": "6.2.0", "status": "affected", "version": "6.0.0", "versionType": "custom" }, { "lessThan": "6.0.0", "status": "affected", "version": "0", "versionType": "custom" } ] } ], "metrics": [ { "other": { "content": { "id": "CVE-2024-21682", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-02-22T17:44:27.088024Z", "version": "2.0.3" }, "type": "ssvc" } } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-94", "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2024-08-28T15:56:52.635Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "product": "Assets Discovery Data Center", "vendor": "Atlassian", "versions": [ { "status": "unaffected", "version": "\u003c 6.0.0" }, { "status": "affected", "version": "\u003e= 6.0.0" }, { "status": "affected", "version": "\u003e= 6.1.0" }, { "status": "affected", "version": "\u003e= 6.2.0" }, { "status": "unaffected", "version": "\u003e= 6.2.1" } ] } ], "descriptions": [ { "lang": "en", "value": "This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). \n\nAssets Discovery, which can be downloaded via Atlassian Marketplace, is a network scanning tool that can be used with or without an agent with Jira Service Management Cloud, Data Center or Server. It detects hardware and software that is connected to your local network and extracts detailed information about each asset. This data can then be imported into Assets in Jira Service Management to help you manage all of the devices and configuration items within your local network.\n\nThis Injection vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to modify the actions taken by a system call which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.\n\nAtlassian recommends that Assets Discovery customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions\n\nSee the release notes (https://confluence.atlassian.com/assetapps/assets-discovery-3-2-1-cloud-6-2-1-data_center-1333987182.html). You can download the latest version of Assets Discovery from the Atlassian Marketplace (https://marketplace.atlassian.com/apps/1214668/assets-discovery?hosting=datacenter\u0026tab=installation).\n\nThis vulnerability was reported via our Penetration Testing program." } ], "metrics": [ { "cvssV3_0": { "baseScore": 7.2, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" } } ], "problemTypes": [ { "descriptions": [ { "description": "Injection", "lang": "en", "type": "Injection" } ] } ], "providerMetadata": { "dateUpdated": "2024-02-20T18:00:00.699Z", "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66", "shortName": "atlassian" }, "references": [ { "url": "https://confluence.atlassian.com/assetapps/assets-discovery-3-2-1-cloud-6-2-1-data_center-1333987182.html" }, { "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1354501606" }, { "url": "https://jira.atlassian.com/browse/JSDSERVER-15067" }, { "url": "https://marketplace.atlassian.com/apps/1214668/assets-discovery?hosting=datacenter\u0026tab=installation" } ] } }, "cveMetadata": { "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66", "assignerShortName": "atlassian", "cveId": "CVE-2024-21682", "datePublished": "2024-02-20T18:00:00.699Z", "dateReserved": "2024-01-01T00:05:33.846Z", "dateUpdated": "2024-08-28T15:56:52.635Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2023-22523 (GCVE-0-2023-22523)
Vulnerability from cvelistv5
Published
2023-12-06 05:00
Modified
2024-08-02 10:13
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- RCE (Remote Code Execution)
Summary
This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets Discovery agent.
References
Impacted products
Vendor | Product | Version | |||||||
---|---|---|---|---|---|---|---|---|---|
► | Atlassian | Assets Discovery Cloud |
Version: >= 1.0.0 Version: >= 1.5.7.0 Version: >= 1.5.7.1 Version: >= 1.5.7.3 Version: >= 1.5.7.4 Version: >= 1.6.1.2 Version: >= 1.6.2.0 Version: >= 1.6.3.0 Version: >= 1.6.4.0 Version: >= 1.6.4.4 Version: >= 1.7.0.0 Version: >= 1.7.1.0 Version: >= 1.7.2.0 Version: >= 1.8.0.0 Version: >= 1.8.1.1 Version: >= 1.8.1.2 Version: >= 1.8.1.3 Version: >= 1.8.1.4 Version: >= 1.8.1.5 Version: >= 1.8.2.0 Version: >= 2.0.0.0 Version: >= 3.1.0 Version: >= 3.1.1 Version: >= 3.1.10 Version: >= 3.1.11 Version: >= 3.1.2 Version: >= 3.1.3 Version: >= 3.1.4 Version: >= 3.1.5 Version: >= 3.1.6 Version: >= 3.1.7 Version: >= 3.1.8 Version: >= 3.1.9 |
||||||
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-02T10:13:48.923Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://confluence.atlassian.com/security/cve-2023-22523-rce-vulnerability-in-assets-discovery-1319248914.html" }, { "tags": [ "x_transferred" ], "url": "https://jira.atlassian.com/browse/JSDSERVER-14925" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Assets Discovery Cloud", "vendor": "Atlassian", "versions": [ { "status": "unaffected", "version": "\u003c 1.0.0" }, { "status": "affected", "version": "\u003e= 1.0.0" }, { "status": "affected", "version": "\u003e= 1.5.7.0" }, { "status": "affected", "version": "\u003e= 1.5.7.1" }, { "status": "affected", "version": "\u003e= 1.5.7.3" }, { "status": "affected", "version": "\u003e= 1.5.7.4" }, { "status": "affected", "version": "\u003e= 1.6.1.2" }, { "status": "affected", "version": "\u003e= 1.6.2.0" }, { "status": "affected", "version": "\u003e= 1.6.3.0" }, { "status": "affected", "version": "\u003e= 1.6.4.0" }, { "status": "affected", "version": "\u003e= 1.6.4.4" }, { "status": "affected", "version": "\u003e= 1.7.0.0" }, { "status": "affected", "version": "\u003e= 1.7.1.0" }, { "status": "affected", "version": "\u003e= 1.7.2.0" }, { "status": "affected", "version": "\u003e= 1.8.0.0" }, { "status": "affected", "version": "\u003e= 1.8.1.1" }, { "status": "affected", "version": "\u003e= 1.8.1.2" }, { "status": "affected", "version": "\u003e= 1.8.1.3" }, { "status": "affected", "version": "\u003e= 1.8.1.4" }, { "status": "affected", "version": "\u003e= 1.8.1.5" }, { "status": "affected", "version": "\u003e= 1.8.2.0" }, { "status": "affected", "version": "\u003e= 2.0.0.0" }, { "status": "affected", "version": "\u003e= 3.1.0" }, { "status": "affected", "version": "\u003e= 3.1.1" }, { "status": "affected", "version": "\u003e= 3.1.10" }, { "status": "affected", "version": "\u003e= 3.1.11" }, { "status": "affected", "version": "\u003e= 3.1.2" }, { "status": "affected", "version": "\u003e= 3.1.3" }, { "status": "affected", "version": "\u003e= 3.1.4" }, { "status": "affected", "version": "\u003e= 3.1.5" }, { "status": "affected", "version": "\u003e= 3.1.6" }, { "status": "affected", "version": "\u003e= 3.1.7" }, { "status": "affected", "version": "\u003e= 3.1.8" }, { "status": "affected", "version": "\u003e= 3.1.9" }, { "status": "unaffected", "version": "\u003e= 3.2.0" } ] }, { "product": "Assets Discovery Data Center", "vendor": "Atlassian", "versions": [ { "status": "unaffected", "version": "\u003c 1.0.0" }, { "status": "affected", "version": "\u003e= 1.0.0" }, { "status": "affected", "version": "\u003e= 3.1.0" }, { "status": "affected", "version": "\u003e= 3.1.1" }, { "status": "affected", "version": "\u003e= 3.1.10" }, { "status": "affected", "version": "\u003e= 3.1.11" }, { "status": "affected", "version": "\u003e= 3.1.2" }, { "status": "affected", "version": "\u003e= 3.1.3" }, { "status": "affected", "version": "\u003e= 3.1.4" }, { "status": "affected", "version": "\u003e= 3.1.5" }, { "status": "affected", "version": "\u003e= 3.1.6" }, { "status": "affected", "version": "\u003e= 3.1.7" }, { "status": "affected", "version": "\u003e= 3.1.9" }, { "status": "affected", "version": "\u003e= 6.0.0" }, { "status": "affected", "version": "\u003e= 6.1.10" }, { "status": "affected", "version": "\u003e= 6.1.11" }, { "status": "affected", "version": "\u003e= 6.1.12" }, { "status": "affected", "version": "\u003e= 6.1.13" }, { "status": "affected", "version": "\u003e= 6.1.14" }, { "status": "affected", "version": "\u003e= 6.1.9" }, { "status": "unaffected", "version": "\u003e= 6.2.0" } ] } ], "credits": [ { "lang": "en", "value": "Bug Bounty" } ], "descriptions": [ { "lang": "en", "value": "This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets Discovery agent." } ], "metrics": [ { "cvssV3_0": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" } } ], "problemTypes": [ { "descriptions": [ { "description": "RCE (Remote Code Execution)", "lang": "en", "type": "RCE (Remote Code Execution)" } ] } ], "providerMetadata": { "dateUpdated": "2023-12-06T15:30:00.483Z", "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66", "shortName": "atlassian" }, "references": [ { "url": "https://confluence.atlassian.com/security/cve-2023-22523-rce-vulnerability-in-assets-discovery-1319248914.html" }, { "url": "https://jira.atlassian.com/browse/JSDSERVER-14925" } ] } }, "cveMetadata": { "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66", "assignerShortName": "atlassian", "cveId": "CVE-2023-22523", "datePublished": "2023-12-06T05:00:02.793Z", "dateReserved": "2023-01-01T00:01:22.333Z", "dateUpdated": "2024-08-02T10:13:48.923Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }