Rewterz
Akira Ransomware – Active IOCs
May 23, 2025
Rewterz
Multiple Cisco Unified Vulnerabilities
May 23, 2025

Multiple Atlassian Products Vulnerabilities

Severity

High

Analysis Summary

CVE-2025-22157 CVSS:7.2

Atlassian Jira Core Data Center and Server and Jira Service Management Data Center and Server could allow a remote authenticated attacker to gain elevated privileges on the system.

CVE-2023-22514 CVSS:7.8

Atlassian Sourcetree for Mac and Sourcetree for Windows could allow a local attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction.

CVE-2024-21703 CVSS:6.4

Atlassian Confluence Data Center could allow a remote authenticated attacker to gain elevated privileges on the system, caused by improper access control in confluence.cfg.xml configuration file. By sending a specially crafted request, an attacker could exploit this vulnerability to escalate privileges.

CVE-2024-21697 CVSS:8.8

Atlassian Sourcetree for Windows and Mac could allow a remote attacker to execute arbitrary code on the system, caused by an unspecified flaw. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.

Impact

  • Code Execution
  • Privilege Escalation

Indicators of Compromise

CVE

  • CVE-2025-22157

  • CVE-2023-22514

  • CVE-2024-21703

  • CVE-2024-21697

Affected Vendors

Atlassian

Affected Products

  • Atlassian Jira Core Data Center 10.5.0
  • Atlassian Jira Core Server 9.12.0
  • Atlassian Jira Core Data Center 10.4.0
  • Atlassian Jira Core Data Center 10.4.1
  • Atlassian Jira Core Data Center 10.3.0
  • Atlassian Jira Core Data Center 10.3.4
  • Atlassian Jira Core Data Center 9.12.0
  • Atlassian Jira Core Data Center 9.12.19
  • Atlassian Jira Core Server 9.12.19
  • Atlassian Jira Service Management Data Center 10.5.0
  • Atlassian Jira Service Management Data Center 10.4.0
  • Atlassian Jira Service Management Data Center 10.4.1
  • Atlassian Jira Service Management Data Center 10.3.0
  • Atlassian Jira Service Management Data Center 10.3.4
  • Atlassian Jira Service Management Data Center 5.12.0
  • Atlassian Jira Service Management Data Center 5.12.19
  • Atlassian Jira Service Management Server 5.12.0
  • Atlassian Jira Service Management Server 5.12.19
  • Atlassian Sourcetree for Mac - 3.4.14
  • Atlassian Sourcetree for Windows - 3.4.14
  • Atlassian Confluence Data Center - 8.7.1
  • Atlassian Sourcetree for Mac - 4.2.8
  • Atlassian Sourcetree for Windows - 3.4.19

Remediation

Refer to Atlassian Security Advisory for patch, upgrade or suggested workaround information.

CVE-2025-22157

CVE-2023-22514

CVE-2024-21703

CVE-2024-21697