Insufficient verification of data authenticity in Assets Discovery - CVE-2023-22523
Published: December 6, 2023 / Updated: March 22, 2024
Assets Discovery
Atlassian
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient verification of data authenticity in the agent application when communicating with the Assets Discovery application. A remote attacker can spoof origin of the server application and execute arbitrary commands on the client system.
Remediation
External links
- https://jira.atlassian.com/browse/JSDSERVER-14893
- https://support.atlassian.com/jira-service-management-cloud/docs/install-asset-discovery-agents/
- https://support.atlassian.com/jira-service-management-cloud/docs/what-are-asset-discovery-agents/
- https://confluence.atlassian.com/security/cve-2023-22523-remote-code-execution-vulnerability-in-assets-discovery-1319248914.html
- https://confluence.atlassian.com/security/cve-2023-22523-rce-vulnerability-in-assets-discovery-1319248914.html
- https://jira.atlassian.com/browse/JSDSERVER-14925