Improper access control in Atlassian Companion App for MacOS - CVE-2023-22524

 

Improper access control in Atlassian Companion App for MacOS - CVE-2023-22524

Published: December 6, 2023 / Updated: June 21, 2024


Vulnerability identifier: #VU83916
CSH Severity: High
CVSS v4: 8.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-22524
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper access restrictions. A remote attacker can trick the victim to visit a specially crafted website and utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow the execution of code.


Affected software

Atlassian Companion App for MacOS

How to mitigate CVE-2023-22524

Install updates from vendor's website.

Atlassian Companion App for MacOS - update to 2.0.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins