Atlassian has warned customers of its Bamboo, Bitbucket, Confluence, Fisheye, Crucible, and Jira merchandise that a pair of significant-rated flaws threaten their protection.
The firm’s July stability advisories element “Servlet Filter dispatcher vulnerabilities.”
One of the flaws – CVE-2022-26136 – is described as an arbitrary Servlet Filter bypass that usually means an attacker could send out a specifically crafted HTTP ask for to bypass personalized Servlet Filters applied by third-party applications to implement authentication.
The scary section is that the flaw enables a remote, unauthenticated attacker to bypass authentication utilised by third-celebration apps. The seriously frightening aspect is that Atlassian isn’t going to have a definitive listing of applications that could be impacted.
“Atlassian has produced updates that resolve the root bring about of this vulnerability, but has not exhaustively enumerated all opportunity implications of this vulnerability,” it extra.
The exact CVE can also be exploited in a cross-web site scripting attack: a specifically crafted HTTP request can bypass the Servlet Filter made use of to validate legit Atlassian Devices. “An attacker that can trick a person into requesting a destructive URL can execute arbitrary JavaScript in the user’s browser,” Atlassian describes.
The next flaw – CVE-2022-26137 – is a cross-origin resource sharing (CORS) bypass.
Atlassian explains it as follows: “Sending a specifically crafted HTTP ask for can invoke the Servlet Filter used to respond to CORS requests, ensuing in a CORS bypass. An attacker that can trick a person into requesting a destructive URL can accessibility the susceptible software with the victim’s permissions.”
Confluence end users have yet another flaw to get worried about: CVE-2022-26138 reveals that one particular of its Confluence apps has a really hard-coded password in place to assistance migrations to the cloud. It spelled out:
If that password falls into the wrong hands, a Confluence implementation is an open up e-book.
The flaws are present in several years-old variations of Atlassian merchandise. Fixes have been issued and have to have updates. Cloudy versions of the goods hosted by Atlassian have previously been mounted.
Information of the vulnerabilities arrives just 6 months following Atlassian’s admission of yet another important flaw in Confluence that was underneath energetic assault.
The Sign up fancies these new ones will also attract the attention of destructive actors. CVE-2022-26136 in all probability represents a considerable possibility to probe long-overlooked integrations for their possible to offer you a path into Atlassian solutions, and from there to do all types of harm with a horrible piece of JavaScript.
With or without this kind of assaults, Atlassian has experienced a hard yr. A few essential flaws that have been present in goods for many years – and an embarrassing cloud outage – are not the sort of point that business shoppers take pleasure in. ®
