CVE-2023-22524

9.6CRITICAL

Key Information

Vendor
Atlassian
Status
Companion for Mac
Vendor
CVE Published:
6 December 2023

Badges

👾 Exploit Exists🔴 Public PoC📰 News Worthy

Summary

Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code.

Affected Version(s)

Companion for Mac >= 1.0.0

Companion for Mac < 1.0.0

Companion for Mac >= 1.1.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit exists.

  • First article discovered by The Hacker News

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database2 Proof of Concept(s)3 News Article(s)
.