Atlassian reveals critical flaws across its product line • The Register

Byregalia

Jul 21, 2022 #Absorbable Modified Polymers Technology, #Advanced Technology Grants Pass, #Aidan'S Professional Technology Services, #Albuquerque Nm Information Technology Recruiters, #Bhd Technology Vr, #Catholic "Information Technology, #Ceo Comcast Technology, #Computer Technology Electronic, #Current Applications Of Rdna Technology, #Disadvantages Technology Law, #Ferrum Technology Services, #Fundamentals Of Medical Laboratory Technology, #Gmu Department Of Information Technology, #Hornborg Alf Technology Effects, #I'M Done Working In Technology, #James V. Arms Technology, #Jurassic Park Technology Analysis, #Liquidmetal Technology News, #Llc, #Mathey Technology And Engineering, #Medical Technology In 500 Bc, #Musc Library Technology Downloads, #New Jersey Technology Office Space, #Pc Ralley Technology, #Ridge Technology Services, #Technology 3x Reverse Etf, #Technology Abuse Use, #Technology Adoption Three Types, #Technology Advantage Info, #Technology And Improving Menial Jobs, #Technology Classroom Building 311, #Technology Companys In Usa, #Technology Distracting Studying Students, #Technology Docking Stations, #Technology Enablement White Paper, #Technology Images For Ppt, #Technology Impact On Finance Departments, #Technology In Chennai, #Technology In Greek Translation, #Technology Into History Lesson, #Technology Is Electricity Ted Talks, #Technology Professionals Of British Columbia, #Technology Relatesecuirty Topics, #Technology Studies Emu, #Technology To Prevent Medication Errors, #Technology Want What Ails Look, #Tesla Technology Roadmap, #Veterinary Assisting Vs Veterinary Technology, #Wentworth Institute Of Technology Animation, #What Is Today'S Technology, #With The Arise Of Technology

Atlassian has warned customers of its Bamboo, Bitbucket, Confluence, Fisheye, Crucible, and Jira merchandise that a pair of significant-rated flaws threaten their protection.

The firm’s July stability advisories element “Servlet Filter dispatcher vulnerabilities.”

One of the flaws – CVE-2022-26136 – is described as an arbitrary Servlet Filter bypass that usually means an attacker could send out a specifically crafted HTTP ask for to bypass personalized Servlet Filters applied by third-party applications to implement authentication.

The scary section is that the flaw enables a remote, unauthenticated attacker to bypass authentication utilised by third-celebration apps. The seriously frightening aspect is that Atlassian isn’t going to have a definitive listing of applications that could be impacted.

“Atlassian has produced updates that resolve the root bring about of this vulnerability, but has not exhaustively enumerated all opportunity implications of this vulnerability,” it extra.

The exact CVE can also be exploited in a cross-web site scripting attack: a specifically crafted HTTP request can bypass the Servlet Filter made use of to validate legit Atlassian Devices. “An attacker that can trick a person into requesting a destructive URL can execute arbitrary JavaScript in the user’s browser,” Atlassian describes.

The next flaw – CVE-2022-26137 – is a cross-origin resource sharing (CORS) bypass.

Atlassian explains it as follows: “Sending a specifically crafted HTTP ask for can invoke the Servlet Filter used to respond to CORS requests, ensuing in a CORS bypass. An attacker that can trick a person into requesting a destructive URL can accessibility the susceptible software with the victim’s permissions.”

Confluence end users have yet another flaw to get worried about: CVE-2022-26138 reveals that one particular of its Confluence apps has a really hard-coded password in place to assistance migrations to the cloud. It spelled out:

If that password falls into the wrong hands, a Confluence implementation is an open up e-book.

The flaws are present in several years-old variations of Atlassian merchandise. Fixes have been issued and have to have updates. Cloudy versions of the goods hosted by Atlassian have previously been mounted.

Information of the vulnerabilities arrives just 6 months following Atlassian’s admission of yet another important flaw in Confluence that was underneath energetic assault.

The Sign up fancies these new ones will also attract the attention of destructive actors. CVE-2022-26136 in all probability represents a considerable possibility to probe long-overlooked integrations for their possible to offer you a path into Atlassian solutions, and from there to do all types of harm with a horrible piece of JavaScript.

With or without this kind of assaults, Atlassian has experienced a hard yr. A few essential flaws that have been present in goods for many years – and an embarrassing cloud outage – are not the sort of point that business shoppers take pleasure in. ®

By regalia