Article Details

Scrape Timestamp (UTC): 2024-03-21 03:37:29.965

Source: https://thehackernews.com/2024/03/atlassian-releases-fixes-for-over-2.html

Original Article Text

Click to Toggle View

Atlassian Releases Fixes for Over 2 Dozen Flaws, Including Critical Bamboo Bug. Atlassian has released patches for more than two dozen security flaws, including a critical bug impacting Bamboo Data Center and Server that could be exploited without requiring user interaction. Tracked as CVE-2024-1597, the vulnerability carries a CVSS score of 10.0, indicating maximum severity. Described as an SQL injection flaw, it's rooted in a dependency called org.postgresql:postgresql, as a result of which the company said it "presents a lower assessed risk" despite the criticality. "This org.postgresql:postgresql dependency vulnerability [...] could allow an unauthenticated attacker to expose assets in your environment susceptible to exploitation which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction," Atlassian said. According to a description of the flaw in the NIST's National Vulnerability Database (NVD), "pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE." The driver versions prior to the ones listed below are impacted - "SQL injection is possible when using the non-default connection property preferQueryMode=simple in combination with application code that has a vulnerable SQL that negates a parameter value," the maintainters said in an advisory last month. "There is no vulnerability in the driver when using the default query mode. Users that do not override the query mode are not impacted." The Atlassian vulnerability is said to have been introduced in the following versions of Bamboo Data Center and Server - The company also emphasized that Bamboo and other Atlassian Data Center products are unaffected by CVE-2024-1597 as they do not use the PreferQueryMode=SIMPLE in their SQL database connection settings. SonarSource security researcher Paul Gerste has been credited with discovering and reporting the flaw. Users are advised to update their instances to the latest version to protect against any potential threats. Goodbye, Atlassian Server. Goodbye… Backups? Protect your data on Atlassian Cloud from disaster with Rewind's daily backups and on-demand restores. Take Action Fast with Censys Search for Security Teams Stay ahead of advanced threat actors with best-in-class threat intelligence from Censys Search.

Daily Brief Summary

MALWARE // Atlassian Patches Critical SQL Injection Vulnerability in Bamboo

Atlassian has released patches for over two dozen vulnerabilities, including a critical SQL injection bug in Bamboo Data Center and Server.

The critical flaw, tracked as CVE-2024-1597 with a CVSS score of 10.0, could be exploited without user interaction.

The vulnerability lies in the org.postgresql:postgresql dependency, potentially allowing an unauthenticated attacker to compromise confidentiality, integrity, and availability.

Affected Bamboo Data Center and Server versions introduced the flaw, but products using default SQL database connection settings are not impacted.

Security researcher Paul Gerste discovered and reported the issue, urging users to upgrade to the latest version of the software.

It's recommended to immediately update affected Bamboo instances to mitigate the risk of exploitation.