Rewterz
Rewterz Threat Alert – Raccoon Infostealer – Active IOCs
January 17, 2024
Rewterz
Rewterz Threat Advisory – CVE-2023-46226 – Apache IoTDB Vulnerability
January 17, 2024

Rewterz Threat Advisory – Multiple Atlassian Confluence Data Center and Atlassian Confluence Server Vulnerabilities

Severity

High

Analysis Summary

CVE-2024-21672 CVSS:8.3

An unspecified error in Atlassian Confluence Data Center and Atlassian Confluence Server could allow a remote attacker to execute code on the system.

CVE-2024-21673 CVSS:8

An unspecified error in Atlassian Confluence Data Center and Atlassian Confluence Server could allow a remote authenticated attacker to execute code on the system.

CVE-2024-21674 CVSS:8.6

An unspecified error in Atlassian Confluence Data Center and Atlassian Confluence Server could allow a remote attacker to execute code on the system.

CVE-2023-22527 CVSS:10

Atlassian Confluence Data Center and Atlassian Confluence Server could allow a remote attacker to execute arbitrary code on the system, caused by a template injection vulnerability. An attacker could exploit this vulnerability to execute arbitrary code on the system.

Impact

  • Gain Access
  • Code Execution

Indicators Of Compromise

CVE

  • CVE-2024-21672
  • CVE-2024-21673
  • CVE-2024-21674
  • CVE-2023-22527

Affected Vendors

Atlassian

Affected Products

  • Atlassian Confluence Data Center 8.0.2
  • Atlassian Confluence Data Center 8.0.3
  • Atlassian Confluence Data Center 8.0.4
  • Atlassian Confluence Data Center 8.1.1
  • Atlassian Confluence Server 8.0.2
  • Atlassian Confluence Server 8.0.3
  • Atlassian Confluence Server 8.0.4
  • Atlassian Confluence Server 8.1.1

Remediation

Refer to Atlassian Website for patch, upgrade or suggested workaround information (login required).

CVE-2024-21672

CVE-2024-21673

CVE-2024-21674

CVE-2023-22527