CVE-2023-22523
Last modified
CVE-2023-22523 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets Discovery agent.. EPSS estimates a 11.15% chance of exploitation in the next 30 days.
Description
This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets Discovery agent.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Assets Discovery Cloud | >= 1.0.0, < 3.2.0 |
| Atlassian | Assets Discovery Data Center | >= 1.0.0, <= 3.1.11 |
| Atlassian | Assets Discovery Data Center | >= 6.0.0, < 6.2.0 |
| Atlassian | Assets Discovery Data Server | >= 1.0.0, <= 3.1.11 |
| Atlassian | Assets Discovery Data Server | >= 6.0.0, < 6.2.0 |
References
- https://jira.atlassian.com/browse/JSDSERVER-14925Issue Tracking, Vendor Advisory
- https://jira.atlassian.com/browse/JSDSERVER-14925Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-22523?
How severe is CVE-2023-22523?
How do I fix CVE-2023-22523?
Are you affected by CVE-2023-22523?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
